Projects · Mini Hostpapa

The Engineering Handbook Volumes

A deep walkthrough of every HostKid volume — platform selection, CloudStack on KVM, and how each chapter builds the next.

Updated Aug 1, 2026 · 16 min read

The Engineering Handbook Volumes

Alright — you read the HostKid intro. You felt the motivation. ProxGen. The pain. The pivot. Then the bigger question: which platform does the hosting company actually run on?

Now let's talk about the roadmap like we're sitting in front of a whiteboard with coffee.

This is not a dry syllabus. This is the engineering handbook — twenty-nine volumes that take you from “what even is a hosting company?” all the way to “I can design, sell, provision, operate, and evolve one.” Each volume builds the next. Skip ahead if you want… but don't be surprised if a later lab assumes you already know why a VLAN exists.

How to use this page

Skim the phases. Dive into the volumes that excite you. Come back when you need orientation. The individual volume folders in the sidebar are where the real docs and labs will land.


The big picture

PhaseVolumesVibe
Foundation0 → 7Business + internet + Linux + platform selection + CloudStack + network + storage + IaC
Platform8 → 13Internal k8s, identity, portal, corporate ERP, DNS, email
Products14 → 18Shared hosting, VPS, object storage, monitoring, logging
Engine & ops19 → 24Flagship provisioning, APIs, automation, security, support, migrations
Mastery25 → 28Solutions engineering, case studies, production ops, future

How we chose the platform

Okay — before we dive volume by volume, let's address the elephant in the rack.

The intro starts with Proxmox and ProxGen. That's real history. I automated VM creation on Proxmox, cut provisioning time dramatically, and proved that declarative ops beats blind clicking.

But HostKid is not “ProxGen with a logo.” It's a hosting company. And hosting companies need more than a hypervisor UI — they need multi-tenant IaaS: accounts, service offerings, networks, templates, quotas, APIs, and a path from “customer clicked Buy VPS” to “VM exists in the right zone with the right isolation.”

So I did what any engineer should do before committing: I evaluated options properly.

What I actually tested

I didn't pick from a blog post. I spent time with four serious paths:

CandidateWhat it isWhy it was in the running
Proxmox VEKVM/LXC hypervisor clusterI already knew it. ProxGen worked. Fast lab wins. Low licensing friction.
VMware vSphereEnterprise hypervisor stackMature HA, familiar in corporate IT, strong operational tooling.
VMware ecosystem (vCloud-style thinking)Commercial cloud management on VMwareHow many established hosts think, but licensing and stack cost matter.
KVM + Apache CloudStackOpen-source IaaS orchestration on KVMBuilt for service providers: zones, offerings, API-first, multi-tenant by design.
Important distinction

Proxmox and vSphere are primarily hypervisor platforms. CloudStack is an IaaS control plane that orchestrates KVM (or other hypervisors). HostKid needs both layers — but the product layer is what separates a lab from a hosting company.

Criteria that actually mattered

I scored each option against what a HostKid would need in year one and year three — not what wins a homelab thread on Reddit.

CriterionWhy it mattered
Multi-tenancy & accountsCustomers, resellers, and internal teams cannot share one flat hypervisor view.
API-first provisioningPortal, billing, and automation must drive the platform — not an operator with a mouse.
Product model (offerings, templates)VPS SKUs, disk sizes, networks — sellable units, not one-off VMs.
Network isolation modelVLANs, guest networks, public vs private — hosting is a networking business wearing a compute hat.
Hosting-industry fitIs this stack used by companies that sell VPS/shared hosting, or mainly by IT teams running internal VMs?
Cost & licensingLab budget vs production reality — especially when you multiply sockets and features.
Operational learning curveComplexity is fine if it buys capability — but hidden complexity kills small teams.
Path from my ProxGen lessonsCloud-init, templates, automation, GitOps — the new stack must respect that discipline.

How each option scored (honestly)

Proxmox — I love it for what it taught me. ProxGen is proof. For a single-team lab or internal IT, it's excellent. For a productized hosting company, you end up building the entire cloud layer yourself: tenant model, product catalog, usage metering hooks, network abstraction, customer-facing API. Doable — but that's half the company before you sell the first VPS.

VMware vSphere — Rock-solid hypervisor. Enterprise credibility. But licensing cost adds up fast, and you still need a cloud management layer on top if you want true IaaS hosting semantics. Great if you're already a VMware shop with budget. Less friendly for an open, documented, learn-in-public journey on modest hardware.

VMware-as-hosting-stack (vCloud Director class thinking) — Conceptually aligned with how big hosts operate. Financially and operationally heavy for HostKid's scope. I kept it in the evaluation because ignoring how the industry actually works would be dishonest documentation.

KVM + Apache CloudStack — This is the one that matched the hosting provider mental model out of the box. Zones, pods, clusters, accounts, domains, service offerings, templates, integrated networking concepts, mature API — the vocabulary of a company selling infrastructure, not just a team cloning VMs.

The decision

HostKid commits to Apache CloudStack on KVM. Proxmox stays in the story as the place where automation discipline was learned — not as the production foundation of the hosting product.

What we did not do

We didn't pretend the decision was religious. We didn't trash tools that solve different problems. Proxmox is still referenced in Volume 3 because understanding why you didn't choose something is as valuable as understanding why you did.

Volume 3 documents the comparison. Volume 4 lives inside CloudStack. The rest of the handbook assumes that choice — but leaves room to revisit criteria if the business changes (multi-region, managed k8s, different hypervisor under CloudStack, etc.).


Volume 0 — Executive Overview

Before we touch a single VM, we zoom out.

What is web hosting? What does a hosting company actually sell — and to whom? We're talking business model, revenue streams, departments that have to talk to each other, the customer lifecycle from signup to churn, and a technical overview that doesn't drown you yet.

Why Volume 0 exists

Engineers who skip the business context build beautiful platforms nobody can sell. Volume 0 keeps us honest: this is a company, not just a lab rack.

You'll walk away with: a company overview, a business architecture sketch, and high-level diagrams you can point at later and say “remember — this box pays for that box.”


Volume 1 — Internet Fundamentals

Everything begins here. No shortcuts.

Internet. TCP/IP. OSI. HTTP. HTTPS. TLS. DNS. Email routing. IPv4. IPv6. Ports. Routing.

If that list feels basic — good. We're going to make it muscle memory, not trivia. Labs mean packet captures, DNS lookups, watching a TLS handshake, firing raw HTTP requests until the layers stop being abstract.

Don't skip this

Half of “hosting mysteries” are just DNS or TLS misunderstandings wearing a trench coat. Volume 1 is how we stop guessing.


Volume 2 — Lab Environment

Volume 1 produced a complete network design on paper. Volume 2 is where that paper becomes a machine you can SSH into, on a laptop, tonight.

We build a simulated datacenter: an Open vSwitch fabric acting as the top of rack switch with real 802.1Q VLANs, a management server VM, a KVM hypervisor VM running under nested virtualization, NFS primary and secondary storage, and an edge firewall doing NAT to the real internet. Then Apache CloudStack goes on top, a zone gets created, and tiny Alpine instances boot inside it.

Why this replaced a Linux fundamentals volume

There is no shortage of Linux tutorials in the world, and reading one more would not move this project forward. What was actually missing was a runnable environment.

You learn more Linux administration in one evening of making nested KVM, OVS trunking, and NFS exports work together than in a month of reading about systemd in the abstract. The Linux knowledge arrives as a side effect of building something that has to work, which is how it sticks.

This is the volume that produces the socle: CloudStack installed, a zone created, a host added, an instance running. Everything from Volume 4 onward has somewhere to land.


Volume 3 — Virtualization & Platform Selection

Bare metal. Hypervisors. Type 1 vs Type 2. KVM. LXC. VMware. vSphere. Proxmox.

Then the question that actually matters for HostKid: what platform do we build the company on?

This volume is split in two:

  1. Fundamentals — how virtualization works, what a hypervisor owns, what an orchestration layer adds.
  2. Decision record — structured comparison of Proxmox, VMware/vSphere, and KVM via CloudStack against real hosting criteria.

You'll see the scoring matrix, the tradeoffs I'm willing to live with, and why CloudStack won for this project — not as universal truth, but as a documented engineering choice you can challenge later.

Don't skip the decision

Jumping straight to CloudStack install without reading Volume 3 is how people copy a stack and can't explain it in an interview. The goal is to own the reasoning.


Volume 4 — CloudStack Platform

Decision made. Now we live inside Apache CloudStack.

Management server. Zones, pods, clusters. KVM hosts. Primary and secondary storage. Physical and guest networking. Templates. Service offerings. Accounts, domains, RBAC. API.

Labs: deploy the control plane, stand up a zone topology, publish offerings, provision through the API until it feels boring — which is the goal.

ProxGen DNA, CloudStack scale

ProxGen taught automation on Proxmox. CloudStack is the factory floor where that automation serves customers, not just internal IT.


Volume 5 — Networking

Traffic has to go somewhere — and it has to stay away from the wrong somewhere.

VLAN. Bridges. NAT. Firewall. HAProxy. Reverse proxy. VPN. BGP basics. Load balancing.

Lab energy: HAProxy in front of VMs until “front door vs backend” stops being a metaphor and becomes a config file you trust.


Volume 6 — Storage

Hosting without durable storage is just a demo that dies on reboot.

ZFS. RAID. Ceph. MinIO. Snapshots. Replication. Backup strategy aligned with CloudStack primary/secondary storage.


Volume 7 — Infrastructure as Code

This is where the old SysOps pain meets the cure.

Terraform. Ansible. Cloud-init. Packer. GitOps.

Remember the story from the intro? Thirty minutes of clicking vs minutes of declare-and-apply? Volume 7 is that story turned into curriculum. Labs: provision through CloudStack and automation — ProxGen thinking, HostKid scale.

ProxGen DNA

If Volume 4 is the factory, Volume 7 is the blueprint language. No more blind hypervisor clicks.


Volume 8 — Kubernetes Platform

Important disclaimer up front: this is an internal platform, not “Kubernetes as a customer product” (that fantasy can wait for later volumes).

k3s. Helm. Ingress. Cert-manager. Storage classes. We use it to host our monitoring, our API, our portal — the company's own control plane.


Volume 9 — Identity

Who are you? What can you touch? Prove it.

Keycloak. OIDC. OAuth. JWT. LDAP. MFA.

Lab: single sign-on that doesn't make you want to throw your laptop. Identity is boring until it's broken — then it's the only thing anyone talks about.


Volume 10 — Customer Portal

The face of the company.

Architecture. Frontend. Backend. Authentication. ERPNext integration. Dashboard.

This is where a human clicks “buy VPS” and starts a chain reaction that eventually hits CloudStack. We're not building a pretty brochure site — we're building the customer control plane.


Volume 11 — Corporate

Internal ERP and billing. The unsexy system that keeps the lights on and runs the company.

ERPNext as all-in-one backbone: products, subscriptions, invoices, payments, customers, taxes, HR, and enterprise resources. Frappe Insights for the owner cockpit: profit signals, high-level metrics, trends. AI-assisted workflows where it reduces manual ops (this stack is familiar territory from building smart ERP solutions in practice).

Labs that matter: sell a VPS, generate an invoice, see revenue show up in the corporate dashboard. Feel the loop from “product SKU” to “customer owes us money” to “I can see margin in Insights”, because without that loop you're running a charity datacenter.


Volume 12 — DNS Platform

Domains are oxygen for hosting.

PowerDNS. API. Domains. Records. Automation.

Lab: automatically create records when a service is born. No more “oops, we forgot the A record” at 11 p.m. during go-live.


Volume 13 — Email Platform

Business email is still a product people pay for — and still a product people hate when it breaks.

Mailcow. SMTP. IMAP. POP3. SPF. DKIM. DMARC. Routing. Spam.

Lab: stand up real business email and prove delivery. Deliverability is half science, half dark arts — we'll document both.


Volume 14 — Shared Hosting

Classic hosting. Still huge. Still relevant.

Apache. NGINX. PHP. MariaDB. WordPress. Virtual hosts. HestiaCP. Automation.

This is the volume for “my agency has fifty WordPress sites and they all need to just work.” Automation is the difference between a business and a burnout.


Volume 15 — VPS Hosting

The product closest to ProxGen's heart.

Provisioning. Templates. Cloud-init. Scaling. Snapshots. Resizing. Recovery. Automation.

From “customer wants a VPS” to “customer has a VPS they can rebuild” — without a SysOps human clicking through a hypervisor UI like it's 2012.


Volume 16 — Object Storage

Buckets. Policies. Users. S3 API. Backups. MinIO.

Object storage is how modern apps stash assets, backups, and “files that shouldn't live on the web root.” We'll treat it like a product, not an afterthought.


Volume 17 — Monitoring

If you can't see it, you can't run it.

Prometheus. Grafana. Loki. Alertmanager. Node Exporter. Blackbox. Dashboards.

This volume is how HostKid stops flying blind. Alerts that mean something. Dashboards you actually open on purpose.


Volume 18 — Logging

Metrics tell you something is wrong. Logs tell you what.

ELK. OpenSearch. Loki. Audit logs. Application logs. Central logging.

When support asks “what did the customer do at 14:02?”, Volume 18 is why you have an answer.


Volume 19 — Provisioning Engine

Okay. Lean in.

This is the flagship. The heart. The volume where HostKid stops being a collection of skills and becomes a system.

A Solutions Engineer is expected to understand how a customer request becomes a working service. Volume 19 is that story, end to end:

Everything before this volume is preparation. Everything after this volume is how you harden, expose, secure, and support what Volume 19 makes possible.

Why this is the interview volume's twin

Volume 25 teaches you to talk about solutions. Volume 19 proves you can build the machine that delivers them. Together, that's systems thinking — not buzzword bingo.


Volume 20 — APIs

Portals shouldn't talk to Terraform with sticky tape.

REST. FastAPI. OpenAPI. Swagger. JWT. Rate limiting. Webhooks. Versioning.

Lab: provision a VPS through a clean REST call. The API is the contract between “product” and “platform.”


Volume 21 — Automation

North star: zero manual work.

Terraform. Ansible. GitLab CI. Pipelines. Secrets. Automation that survives a human going on vacation.

If something still requires a tribal-knowledge SSH session, Volume 21 is where we hunt it down and kill it with a pipeline.


Volume 22 — Security

Hosting companies are targets. Act like it.

Vault. Firewalls. CrowdSec. Fail2ban. SSH hygiene. TLS. Secrets. Backups. RBAC. Compliance thinking.

Security is not a volume you “finish.” It's a volume you keep reopening — and that's fine. We'll build the baseline like adults.


Volume 23 — Customer Support

Support is an engineering function wearing a friendly face.

Ticket lifecycle. Incident response. Runbooks. Escalation. Troubleshooting. Knowledge base.

When production hurts, Volume 23 is why the team doesn't invent a process mid-fire.


Volume 24 — Migrations

Customers arrive with baggage. Help them move it without dropping it.

WordPress. Email. DNS. VPS. Databases. Rollback. Cutover. Validation.

Migrations are where trust is won or lost. We'll document the scary parts on purpose.


Volume 25 — Solutions Engineering

The interview volume. The “can you think like someone who sits between Sales, Engineering, Ops, and the customer?” volume.

Requirements gathering. Discovery meetings. Technical questionnaires. Architecture workshops. Solution design. Risk analysis. Migration planning. Partner onboarding. Technical presentations. POCs. Documentation. Acceptance criteria. Project handover. Communication with everyone who will either unblock you or bury you.

This is where soft skills meet hard stack

You already built the platform in earlier volumes. Volume 25 is how you sell and shape it without promising magic.


Volume 26 — Case Studies

Stories. Full ones. Not LinkedIn fluff.

Examples we'll write like real engagements:

  • Customer migrating 300 WordPress sites
  • SaaS company that needs high availability
  • Digital agency onboarding 500 domains
  • University deploying email
  • E-commerce that needs auto-scaling
  • Company leaving cPanel for CloudStack-based VPS
  • Reseller launching a white-label hosting business

Each case study packs: business context, requirements, constraints, proposed architecture, implementation plan, risks and mitigations, validation, rollback, lessons learned.


Volume 27 — Production Operations

Day-to-day reality. The unglamorous excellence.

Capacity planning. SLA / SLO / SLI. Incident management. Change management. Maintenance windows. Patch management. Disaster recovery. Business continuity. Cost optimization. Datacenter expansion.

This is how the company survives year two.


Volume 28 — Future Evolution

Where could this go next?

Multi-region. GPU hosting. Managed Kubernetes for customers. Serverless. Private cloud offerings. IPv6-only environments. AI-assisted support. Self-service migration wizards.

We won't build all of it tomorrow. We will learn to roadmap like a platform team — ambition with sequencing.


How to navigate from here

  1. Keep the intro for motivation and context.
  2. Read How we chose the platform on this page before you install anything.
  3. Use this page when you need the full volume story.
  4. Stuck on a skill or decision? Open Books That Help You Decide — the reading shelf mapped to each phase.
  5. Open each volume folder in the sidebar when you're ready to go deep and get your hands dirty.
  6. Treat Volume 19 as the summit you're climbing toward — and Volume 25 as the skill of explaining the climb.
Ready when you are

Volume 0 is waiting. Let's build a hosting company the honest way — one volume, one decision, one scar at a time.