Services & your first website
Everything so far leads here. You'll install a real web server, start it, open the firewall, and publish your own page. This is where the family differences stack up, so it's the perfect final exam for Unit 3.
You will learn
- What a service is, and how to control one with
systemctl(the same on both) - Apache:
httpdon Rocky vsapache2on Ubuntu - Firewalls:
firewalldon Rocky vsufwon Ubuntu, and how not to lock yourself out
Services and systemctl
A service (old-school name: daemon) is a program that runs quietly in the background, waiting for work. sshd waits for logins and a web server waits for browsers. Both families use systemd to manage services, so these commands are identical:
systemctl status NAME # is it running? (no sudo needed) sudo systemctl start NAME # start it now sudo systemctl stop NAME # stop it now sudo systemctl restart NAME # stop + start (after changing settings) sudo systemctl enable NAME # start automatically at boot sudo systemctl enable --now NAME # enable AND start, in one go
start means “right now” and enable means “every time the computer boots.” They're separate on purpose, which is why enable --now is so handy. (Lesson 15 goes much deeper: unit files, old-style service and /etc/init.d, and writing your own service.)
The Apache web server, two ways
Apache is one of the most popular web servers in the world, and it's the same software on both families. But look how many little things differ:
| Rocky / RHEL | Ubuntu / Debian | |
|---|---|---|
| Package & service name | httpd | apache2 |
| Starts after install? | No. You have to enable it yourself. | Yes. It's running immediately. |
| Firewall | firewalld: on, blocks web traffic | ufw: off until you enable it |
| Settings folder | /etc/httpd/ | /etc/apache2/ |
| Log files | /var/log/httpd/ | /var/log/apache2/ |
| Runs as user | apache | www-data |
| Extra security guard | SELinux | AppArmor |
| Where your web pages go | /var/www/html/ on both | |
Build it: step by step
# 1. install sudo dnf install -y httpd # 2. start it now + at every boot sudo systemctl enable --now httpd # 3. open the firewall for web traffic sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --reload # 4. write your page echo '<h1>My first site</h1>' | sudo tee /var/www/html/index.html # 5. test it curl localhost
firewalld has two copies of its rules: runtime (active now) and permanent (saved). --permanent saves the rule and --reload makes the saved rules active.
# 1. install (it starts by itself) sudo apt update sudo apt install -y apache2 # 2. check it's running systemctl status apache2 # 3. firewall: allow SSH FIRST, then web, then turn it on sudo ufw allow OpenSSH sudo ufw allow 'Apache' sudo ufw enable # 4. write your page echo '<h1>My first site</h1>' | sudo tee /var/www/html/index.html # 5. test it curl localhost
ufw starts off. If you enable it without allowing OpenSSH first, it cuts off your own SSH connection. Try it in the practice terminal and see what happens! 😬
curl fetches a web page and prints its HTML. It's how admins test a web server without opening a browser. On a real network, you can then open http://SERVER-IP in any browser and see your page.
A firewall is the bouncer at the door: only the services you list get in. Tutorials (and AI chatbots!) sometimes say “just disable the firewall” or “turn off SELinux.” That makes the error go away by removing the security. Open exactly the service you need, and nothing more.
Try it: launch your site 🚀
Do it on one family, then switch families and do it again. Watch for the differences.
Quick check
1. You installed httpd on Rocky but curl localhost says “Couldn't connect.” Why?
✓ Exactly. Ubuntu starts services for you, Rocky waits for you to decide.
2. You're connected to an Ubuntu server over SSH. What must you do before sudo ufw enable?
✓ Always let yourself in before you lock the door.
3. What's the difference between systemctl start and systemctl enable?
✓ Use enable --now to do both at once.