BADR TAJINI · ESILV · 2026–2027

Set up once, then follow the same labs

Recommended: your own laptop. No school-issued server is required or supplied.

Start here · Compare environments

This checklist follows the useful order from Badr's Hades setup: choose the machine → install tools → check Docker → open the course and project folders → run a small container → keep evidence. It does not copy Hades's private addresses, accounts or institutional provisioning script. Follow only your lane, not every section.

A. Local laptop — the default

  1. Follow the Windows, Mac or Linux installation panel on Start here. On Windows, Ubuntu 24.04 under WSL2 gives you a Linux terminal; keep Docker Desktop integration enabled and do not install a second Docker Engine inside that Ubuntu.
  2. Keep the full student course folder and your private project repository in separate folders. In WSL, use your Ubuntu home directory for both.
  3. Continue at D. Shared checks below. No host address, server fingerprint or SSH tunnel is needed.

If you choose a local Ubuntu VM, the next section's Ubuntu installation commands apply inside that VM. Its console and local networking replace a cloud account; no VPS purchase is necessary.

B. Optional Ubuntu VPS — your own machine

1. Choose and secure access

Choose plain Ubuntu 24.04 LTS, x86_64/amd64, at least 2 vCPU / 4 GiB RAM / 40 GiB disk. Record the price and cancellation procedure privately. Set billing notifications where available; an alert is not necessarily a spending cap.

Use the provider dashboard's documented SSH-key setup. On your laptop, create a dedicated key only if this name is unused; do not overwrite an existing key:

ssh-keygen -t ed25519 -f "$HOME/.ssh/docker-course" -C docker-course

Choose a passphrase. Give the provider only the .pub file. The provider supplies the server address and initial login name; Badr does not issue these for your own server. In the provider's trusted web console, display its host fingerprint:

sudo ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub

On your laptop, enter the two values when prompted and connect:

read -r -p 'Your server address: ' LAB_HOST
read -r -p 'Your server login name: ' LAB_USER
ssh -i "$HOME/.ssh/docker-course" "$LAB_USER@$LAB_HOST"

Compare the first-connection fingerprint with the console value. Stop on a mismatch. If only a root login is supplied, use the provider's documented procedure to create a named sudo-capable account and install your public key for it. Verify the new account in a second terminal before closing your original session. Do the remaining work through that named account.

In the provider firewall/security group, allow inbound SSH only from your own current public IP where possible. Do not open application, database or Docker API ports. Keep provider-console access available for recovery. Published Docker ports can bypass UFW rules, so UFW alone is not proof of private exposure.

2. Inspect before installing — in the Ubuntu terminal

cat /etc/os-release
uname -m
nproc
free -h
df -h /
command -v docker || true

Expected: Ubuntu 24.04 and x86_64; enough memory and disk. If Docker already exists, run section D first. Do not replace a working installation or delete its containers blindly. These commands are for a fresh, self-owned Ubuntu machine, not WSL with Desktop, macOS, or Codespaces.

3. Install Docker from its official Ubuntu repository

Run one block at a time. sudo authorizes changes to your own machine; apt installs packages. If a command fails, stop and report the error.

sudo apt update
sudo apt install ca-certificates curl git python3 python3-venv jq
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc

Register the package repository:

sudo tee /etc/apt/sources.list.d/docker.sources <<EOF_DOCKER
Types: deb
URIs: https://download.docker.com/linux/ubuntu
Suites: noble
Components: stable
Architectures: amd64
Signed-By: /etc/apt/keyrings/docker.asc
EOF_DOCKER
sudo apt update
sudo apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
sudo systemctl enable --now docker

This installs the current stable packages for a beginner setup. It does not reproduce the exact package versions recorded for Hades. The course's locked versions remain in 0_technical_support/versions.env; record your versions rather than claiming an exact reference match. Do not downgrade an existing host just to imitate Hades.

Allow your named account to run Docker, if that is acceptable on this personal lab machine:

sudo usermod -aG docker "$USER"

Docker-group access is effectively root access. Do not grant it to unknown users. Log out and reconnect so the new group takes effect; then continue at D. If Docker still says permission denied, ask for help rather than changing socket permissions.

Sources: Docker's Ubuntu installation and Linux post-installation.

4. Browser access when a lab starts its web container

Run the lab's Docker commands in the VPS terminal. Its 127.0.0.1 is the VPS, not your laptop. Keep the app bound to loopback.

In a separate laptop terminal, enter your host and login again, then leave this tunnel running:

read -r -p 'Your server address: ' LAB_HOST
read -r -p 'Your server login name: ' LAB_USER
ssh -i "$HOME/.ssh/docker-course" -N -L 8080:127.0.0.1:8080 "$LAB_USER@$LAB_HOST"

Open http://127.0.0.1:8080 in your laptop browser. Use Ctrl+C in that terminal to close the tunnel. A connection failure before the lab's container starts is expected; a tunnel does not start an application.

C. Optional Codespaces

  1. Open your private project repository on GitHub. Choose Code → Codespaces → Create codespace, using a small machine initially. Check personal allowances and who pays before creation.
  2. Run section D in its terminal. A Codespace is a development container; Docker-in-Docker support and Compose must be available. If Client exists but Server does not respond, ask for help configuring the official Docker-in-Docker dev-container feature. Do not run the VPS systemd installer inside it.
  3. Use the Ports tab for port 8080 and keep visibility Private. The browser's forwarded URL can differ from the lab's internal 127.0.0.1:8080; run lab curl probes in the Codespaces terminal.
  4. Save course and project files under /workspaces, in separate folders. Commit and push your work before stopping. Do not assume Docker volumes will survive a dev-container rebuild.
  5. Stop the Codespace after class; retained storage still counts. Delete it only once your required work has been saved elsewhere.

References: Codespaces environment, forwarded ports, Docker-in-Docker feature.

D. Shared checks — in the terminal where Docker will run

git --version
docker version
docker compose version
docker buildx version

Git, Compose and Buildx should print versions; Docker must show Client and Server. A Client-only result is not ready. Note your OS, CPU architecture and versions. These are installation checks, not proof that all six labs pass.

Open your project

Follow the current setup page to open the supplied application. No school server, fixed /opt or /srv directory, team ID or repository invitation is needed to try TD0.

Start TD0, then use its Next link. The lab helper locates supplied course files from the project and handles evidence packaging later. You record the actual result; it cannot certify Docker behavior.

From TD2 onward you need your own project repository and private GHCR package permissions. Renting a VPS does not provide registry permissions.

Support: Discord remotely; Badr on campus. Send the command, error and OS. Never share secrets. On a paid server, save your work and cancel/delete the rented resources according to the provider's terms when finished; shutting down a VM may leave charges running.