Posts

Showing posts from September, 2026

I Was Deploying Wrong — What Subnet, Internet Gateway & NAT Gateway Taught Me About My NGold EC2

Image
Day 8: I Was Deploying Wrong — What Subnet, Internet Gateway & NAT Gateway Taught Me About My NGold Attack People asked me yesterday after my AWS attack alert: "SirVick, do you even know subnet, Internet Gateway, NAT Gateway?" I laughed because 2 days ago I didn't. I just clicked "Launch EC2" and thought AWS does networking automatically. After my instance at 32.196.145.76:3000 was scanned, I finally sat down to learn VPC networking. And I realized I was deploying wrong from Day 1. Let me explain networking like I explained Docker with garri and cooler — Port Harcourt style, so you never forget. VPC = Your Fenced Family Compound VPC (Virtual Private Cloud) is like your family compound in PH. When you create AWS account, AWS gives you default VPC — like government giving you land with fence already built. Inside that fence, you can build houses (subnets), you have main gate (Internet Gateway). Without fence, your house is on the road — anyone enters....

Bash Scripting Saved Me — How I Automated NGold Deployment After AWS Attack Alert on My EC2

Image
Day 7: Bash Scripting Saved Me — How I Automated NGold Deployment After AWS Attack Alert on My EC2 Yesterday was supposed to be just another Linux day. I woke up early in Port Harcourt, ready to write about file permissions and processes for Day 6. My Netflix Clone NGold was live and happy at 32.196.145.76:3000. I had just pushed a new build, Docker was running, and I was feeling like a real DevOps engineer. Then at 9:12 PM, my phone buzzed. AWS email: "Your Amazon EC2 instance has been identified as being targeted for penetration attempts." My heart cut instantly. I opened the email with shaky hands. AWS GuardDuty was flagging my t2.micro instance. Someone, or some bot, was scanning my IP from different locations. The report mentioned SSH brute force attempts and suspicious port probing. I have never felt that kind of panic in this 7-day journey. I spent 6 days building, now is my project about to become someone's crypto mining machine? I did what every junior De...

Understanding Linux Environment — The Real Engine Behind My AWS Cloud Deployment

Image
After I deployed my Netflix Clone NGold to AWS EC2 on Day 2, I honestly thought the hard part was over. From Port Harcourt, fighting git push errors, to finally seeing my app live on 32.196.145.76:3000, I felt like a Cloud Engineer already. I was wrong. The real DevOps journey started the moment I SSHed into that black terminal screen. AWS EC2 gives you a virtual computer, but Linux is the operating system that powers it. Without understanding the Linux environment, your Cloud deployment will not survive one day in production. Docker, AWS, Kubernetes — all of them run ON Linux. That was my Day 6 lesson. 1. The Linux File System – Where Everything Actually Lives Unlike Windows with C: and D: drives, Linux has a single tree starting from root (/). This confused me at first. Where is my app? Where are logs? I learned: /home/ubuntu is where my NGold code lives, /var/log is where all error logs hide (this saved me when my container crashed), /etc holds all system configs, and /tmp is ...

Step By Step on How I Setup NGINX Reverse Proxy to Hide Port 3000 on AWS EC2

Image
Few days ago, I made a big mistake — I left Port 3000 open to the world on my EC2. Anyone could access http://my-ip:3000 directly. That is dangerous because hackers can attack your Node.js process directly.  Today, I fixed it properly with NGINX Reverse Proxy. After this fix, my MERN app now runs on clean; http://IP without any port number, and port 3000 is completely private.   What is Reverse Proxy? (Simple beginner explanation) Imagine your EC2 is a big office building. Your Node.js app is a boss sitting in Room 3000 inside. Before, you allowed visitors to go straight to Room 3000. That is risky. Reverse Proxy is like putting a professional receptionist (NGINX) at the main entrance (Port 80). All visitors must come to reception. Receptionist will go inside, collect what you need from Room 3000, and bring it to the visitor. No visitor ever enters Room 3000 directly.  That is what the diagram above shows.  User -> NGINX (Port 80/443) -> Node.js (Private P...

My First EC2 Mistake: I Left Port 3000 Open and Almost Got Hacked

Image
Yesterday I made the most beginner mistake in my DevOps journey. I deployed my MERN app to AWS EC2, it was live and I was happy. But I left port 3000 open to the whole internet. Let me explain. My Node app runs on port 3000. To test quickly, I went to EC2 Security Group and added: Custom TCP, Port 3000, Source 0.0.0.0/0. That means anyone on the internet can access my server on port 3000. I thought "I will close it later." I forgot. Two hours later I ran pm2 logs and saw strange requests from Netherlands, Vietnam and US IPs: /.env, /.aws/credentials, /admin, /wp-login.php. Someone was scanning my open port trying to steal secrets!  I panicked. I am in Port Harcourt but my server in us-east-1 was being attacked live.  How I fixed it: I rushed to AWS Console > EC2 > Security Groups > Inbound Rules and deleted the port 3000 rule. I configured NGINX as reverse proxy. NGINX now listens on port 80 and 443 and forwards internally to port 3000. My app still runs on 3000 but ...

Day 3: No Light, But I Finally Understood GitHub & Docker (With Garri & Bus Analogy) 😂

Image
  Yesterday NEPA took light — 124 views with laptop off! Today light is back, let's gist! I used to think GitHub & Docker na big grammar. Until I explained it to my neighbor selling akara:1. GitHub = Your Mama's Soup Pot & Note Book You know how mama writes soup recipe in a book? If soup spoils, she checks the book to remember yesterday's recipe.GitHub is that book for code.I cook code (add pepper). I write inside GitHub book: "Today I added salt" (git commit -m "added salt").  If I spoil the soup (code breaks), I open book and go back to yesterday's sweet soup (git revert) That "src refspec main" error? Na because I tried to serve soup without writing recipe first!  No more "my code disappeared" story!2. Docker = Your Cooler of Rice for Delivery Imagine you cook jollof for a customer in PH. You want to deliver to Lagos and it must still taste same, hot, with same plate, spoon. If you carry pot open for bus, everything spi...

How I Deployed Netflix Clone (NGold) to AWS EC2 - Live at 32.196.145.76:3000 [Docker + Nginx Guide]

I finally deployed my Netflix clone project NGold to AWS EC2! After 3 failed attempts with permission errors and Nginx crashing, it's now LIVE at http://32.196.145.76:3000 Here's exactly how I did it for anyone trying to deploy a React frontend to EC2. My Stack  Frontend: React (from my GitHub: Sirvickcloud91/netflix-frontend-1)  Server: AWS EC2 Ubuntu  Tools: Docker, Nginx, Git  Live IP: 32.196.145.76:3000 Step 1: Launch EC2 and Open Port 3000 Most beginners forget Security Group. You must allow inbound rule: Type: Custom TCP Port: 3000 Source: 0.0.0.0/0 If you don't do this, your app will run but you won't see it in browser! Step 2: Clone and Dockerize On your EC2: git clone https://github.com/Sirvickcloud91/netflix-frontend-1.git cd netflix-frontend-1 docker build -t ngold-frontend . docker run -d -p 3000:3000 ngold-frontend Fix Nginx (My Biggest Headache) Nginx kept showing 502 Bad Gateway. The fix: sudo systemctl restart nginx sudo nano /etc/nginx/sites-availab...

How I Fixed GitHub Error: failed to push some refs to github.com in 2026

Today I was deploying my Netflix clone project (NGold) to GitHub when I got this frustrating error: ! [rejected] main -> main (fetch first) error: failed to push some refs to 'https://github.com/Sirvickcloud91/netflix-frontend-1.git' If you are seeing this error, don't panic. I fixed it in 2 minutes. Here is how. Why this Error happens. This error means your GitHub repository has files that your local computer does not have. In my case, I added screenshots on GitHub website, but my laptop didn't have those screenshots. GitHub is telling you: "Hey, fetch first before you push!"  My Situation, I was working on: Project: Netflix Clone - NGold Live: 32.196.145.76:3000 Repo: Sirvickcloud91/netflix-frontend-1 Error happened after adding 6 screenshots to GitHub. SOLUTION - 2 Commands Only Open your terminal in VS Code and run: Step 1: Pull with rebase: (git pull origin main --rebase). This will download the missing files from GitHub to your laptop without creating...