Skip to main content
bash TV

How to Deploy, Secure, and Automate Full-Stack Web Apps – Course for Beginners

freeCodeCamp.org

44.7K views15 Sept 2026

YouTube

Learn how to take a web application from local development to a secure, live production environment. You will learn how to manually configure an Ubuntu server, set up essential runtimes, establish automated CI/CD pipelines, and secure your site using HTTPS and Cloudflare. By tackling everything hands-on before introducing automation, you will gain a deep, foundational understanding of full-stack deployment and how to reliably host complex systems. ⭐️ Links and resources ⭐️ Course handbook and documentation: https://github.com/ImadSaddik/FullStackDeploymentHandbook Project source code: https://github.com/ImadSaddik/ImadSaddikWebsite DigitalOcean ($200 free credit): https://m.do.co/c/4f9010fc5eb3 SSH config documentation: https://www.ssh.com/academy/ssh/config Porkbun domain registrar: https://porkbun.com/ Let's Encrypt: https://letsencrypt.org/ Certbot: https://certbot.eff.org/ Cloudflare: https://www.cloudflare.com/ Nmap network scanner: https://nmap.org/ Pre-commit framework: https://github.com/pre-commit/pre-commit Pipx: https://github.com/pypa/pipx GitHub Actions documentation: https://docs.github.com/en/actions Meilisearch UI dashboard: https://github.com/eyeix/meilisearch-ui GoAccess log analyzer: https://goaccess.io/ Btop resource monitor: https://github.com/aristocratos/btop Locust load testing framework: https://docs.locust.io/ NCDU disk usage analyzer: https://dev.yorhel.nl/ncdu/man OWASP ZAP scanner: https://www.zaproxy.org/ Crontab Guru: https://crontab.guru/ Mozilla HTTP Observatory: https://observatory.mozilla.org/ Security Headers audit: https://securityheaders.com/ Nginx Playground: https://nginx-playground.wizardzines.com/ To connect with Imad Saddik, check out his social accounts: LinkedIn: https://www.linkedin.com/in/imadsaddik/ YouTube: https://www.youtube.com/channel/UC1VK2jL-sTIBUK2riD0DkKw ❤️ Support for this channel comes from our friends at Scrimba – the coding platform that's reinvented interactive learning: https://scrimba.com/freecodecamp Links mentioned in the course: ⭐️ Contents ⭐️ - 0:00:00 Introduction - 0:01:50 Problem statement & philosophy - 0:06:23 Module overview & roadmap - 0:16:25 Repo & handbook resources - 0:17:21 Module 1: Foundation - 0:20:30 Droplet provisioning - 0:25:33 SSH keys & ED25519 generation - 0:35:15 First login & package updates - 0:40:05 Sudo users & disable root login - 0:49:56 SSH configs & client shortcuts - 0:57:00 UFW firewall lockdown - 1:07:59 Fail2ban defense setup - 1:14:24 DigitalOcean recovery console - 1:19:28 Module 2: Application runtime - 1:21:40 SCP code transfer & permissions - 1:27:48 Python virtualenv & FastAPI - 1:34:14 Node.js, NVM & pnpm setup - 1:38:16 Fix OOM errors with swap memory - 1:46:53 Local tests via SSH tunneling - 1:52:01 Gunicorn & Uvicorn workers - 2:00:46 Supervisord process monitoring - 2:06:01 Memory & zombie processes via Btop - 2:21:08 Sync URLs with Vite proxy - 2:31:58 Nginx reverse proxy installation - 2:50:28 Fix 502 Gateway & permissions - 3:01:55 Security headers & CSP - 3:23:20 Module 3: Data & search - 3:26:51 Self-host Meilisearch on Ubuntu - 3:28:30 Standard vs system users - 3:34:26 DB dumps, snapshots & migration - 3:41:40 Secure keys & systemd service - 3:51:55 Seed search & connect FastAPI - 4:05:40 Automate daily snapshots - 4:08:45 Meilisearch UI dashboard - 4:16:52 Module 4: Global delivery - 4:19:00 Custom domain registration - 4:23:43 Configure DNS A & CNAME records - 4:29:07 SSL via Let's Encrypt & Certbot - 4:36:50 Automate 90-day SSL renewals - 4:42:09 Cloudflare CDN edge caching - 4:59:47 Restore real visitor IPs in Nginx - 5:14:37 Eliminate SPA soft 404 traps - 5:23:48 Port scanning with Nmap - 5:29:37 Module 5: Automation pipeline - 5:34:11 GitHub Rulesets branch protection - 5:39:14 Local hygiene via pre-commit - 5:57:31 Modular GitHub Actions CI - 6:30:07 Software Composition Analysis - 7:03:15 SAST scanning with Bandit - 7:13:40 Live Meilisearch integration testing - 7:26:55 E2E testing via Playwright - 7:41:48 DAST scanning with OWASP ZAP - 8:00:43 Frontend build & artifact generation - 8:03:34 Automated backup & cleanup scripts - 8:07:28 Passwordless visudo configuration - 8:11:05 Secrets & manual deployment reviews - 8:41:35 Sync production files via rsync - 8:46:26 Dynamic env file generation - 8:50:26 Atomic venv swap & rollbacks - 8:58:56 Rolling restarts (Supervisor/Nginx) - 9:09:23 Module 6: Optimization & maintenance - 9:10:22 Parsing Nginx logs via GoAccess - 9:14:58 Password-protected analytics dashboard - 9:20:51 Solving CSP restrictions via nonces - 9:29:57 Aggregating compressed logs via zgrep - 9:33:05 Hourly automated dashboard updates - 9:34:21 Real-time server monitoring via Btop - 9:42:26 Block malicious bots with UFW - 9:50:30 Load testing & latency via Locust - 10:05:38 Disk usage analysis via NCDU - 10:08:14 JournalD & Nginx log retention - 10:10:40 Monthly cron maintenance scripts - 10:14:10 Scheduled deep DAST scanning - 10:25:19 Conclusion

Join the discussion

Sign in to join the discussion

Sign in