Service · Systems administration

Server management

Taking over servers always begins with a simple question that is seldom written down anywhere: what runs on these machines, and who relies on it? In a company of forty people the answer rarely fits in three lines. There is a directory, a file share, a database behind the accounting package, a box that pushes orders to the carrier, and a print server whose password nobody remembers. Our first job is to write that list; our second is to make sure nothing on it dies without warning. Your machines may sit in the office, in a rack at a hosting provider or at OVHcloud, and the method stays the same.

Named accounts
no shared administrator password
Fixed window
for applying patches
Test restore
at the rhythm set in the contract
Monthly report
readable by a non-technical owner

Where this service reaches

We do not start from tooling. We start from the list of services your business cannot trade without, and the alert thresholds follow from it.

Put your scope to an engineer

Inventory of roles

What each machine carries: directory, files, the database behind Sage, Cegid or Divalto, a web server, a mail relay. Each entry also gets the end-of-support date of its operating system.

Hardware health

SMART values, RAID array state, power supplies and temperatures read through iDRAC, iLO or the hosting provider console. A weakening disk triggers a warranty claim rather than a wait.

Patching

Windows inside an agreed window; Linux with particular attention to the PHP and database versions your website depends on. Always with a way back.

Certificates and domains

An expired certificate halts a mail flow or a shop as thoroughly as a failed disk. Certificate, domain and licence expiry dates live in a calendar we watch.

Backups under watch

Daily review of job results and, at the agreed rhythm, an actual rebuild of one chosen server to prove the copies are good for something.

Change log

Who did what, when and why. That single document is what makes NIS2 preparation or an audit run along ISO 27001 lines bearable, and a change of supplier painless.

The way an engagement runs

The first weeks go into understanding what exists. After that the rhythm is familiar to everyone, your own staff included.

01

Access

Named administrative accounts and an encrypted channel, usually a VPN with two-factor authentication.

02

Baseline

Disks, overdue patches, backups, logs. Anything urgent is fixed straight away, the rest goes into a plan.

03

Monitoring

Probes go in and we decide, service by service, who receives which alert and at what hour.

04

Rhythm

Fixed windows, a monthly report and a short video call with whoever makes the decisions on your side.

Monitoring that fires four hundred alerts a day has stopped monitoring anything. After a fortnight nobody reads the messages and the real outage drowns in the noise. So we spend time on thresholds, group related alerts together and silence the ones that ask for no action. An alert should mean a human has something to do, right now.

Questions and answers

No, and it is usually easier: power, cooling and connectivity are already someone's profession. At OVHcloud, Scaleway or elsewhere we work through the remote console, and when a part fails the physical work goes through the provider's ticket. If the machines stay in your office, what we really ask for is a decent UPS and a management interface we can reach.

Every month it stays in production adds risk, and the argument no longer convinces an insurer or a NIS2 file. We plan the move of its roles onto a supported version or a virtual machine, beginning with whatever migrates painlessly. Until then the box is isolated on the network, its remote access closed and its monitoring tightened.

Patches flagged critical skip the queue: we propose a slot the same day. The rest wait for the monthly window. When CERT-FR warns about a flaw already being exploited in a product you run, we write to you before a slot even exists, with the workaround to apply immediately.

Yes. Passwords live in a vault you hold a key to, administrative accounts are named, and the documentation belongs to you. If you ever change supplier, everything is handed over without negotiation, which is also plain common sense in a GDPR processing agreement.

Show us your servers

Tell us what you have and where it runs. We come back with our questions and a realistic monthly figure for running it.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.