Live data from Hacker News

Screw it, I’ll host it myself

markozivanovic.com

261–270 of 495 posts

Re: Screw it, I’ll host it myself

#261

The problem I have always had when building elaborate home server setups is the "set it and forget it" nature of the systems I've installed bites me in the ass. Since it's not my full-time job to manage these systems, I'm really not familiar with them the way I might be with the systems I manage at work. These systems cruise along for years, and when something finally does go belly-up, I can't remember how I set it u…

These systems cruise along for years, and when something finally does go belly-up, I can't remember how I set it up in the first place.

This happened a few times to me over the years and then I was lucky enough to go on a packer/terraform course.

Now everything is scripted and stored in git. A Gitlab job rebuilds the VMs from scratch every two weeks to include the latest bugfixes and updates.

It was a lot of work at first but actually most of it was a learning experience.

Re: Screw it, I’ll host it myself

#262
post #191

Y'know what, Although I'm currently self hosting my email, my websites, my storage, my SQL, my Active Directory etc., I'm also in the process of migrating the whole lot to Azure and/or independent hosting. Why? It's just too much hassle these days; I want my down-time to be no longer dictated by my infrastructure. I don't want to have to spend off-work hours making sure my boxes are patched, my disks are raided, my o…

Did you ever receive complaints that your emails are ending up in spam folder for Gmail/Outlook/ ? How about you receiving a lot of spam emails?

Nope. I'm on a static business IP, with DNS all set up correctly. I've also got SPF records set up, but I don't think they get used, as I use my ISPs smarthost for relaying mail through.

I do get a lot of incoming spam though, but I think that's more to do with some of my email addresses being over 20 years old.

Re: Screw it, I’ll host it myself

#263

The problem I have always had when building elaborate home server setups is the "set it and forget it" nature of the systems I've installed bites me in the ass. Since it's not my full-time job to manage these systems, I'm really not familiar with them the way I might be with the systems I manage at work. These systems cruise along for years, and when something finally does go belly-up, I can't remember how I set it u…

Nix helps with this. Or at least it intends to. I still need to track down what's vulnerable and what isn't, but most of my setup is reproducible thanks to Nix.

I've read people admitting that Nix can give you a lot of work from time to time, when something isn't already available for Nix (which happens more often than, say, for Debian), and you want to add it to your system. Is that true in your experience? I may be phrasing it wrong.

What is the learning curve of Nix?

Re: Screw it, I’ll host it myself

#264

Y'know what, Although I'm currently self hosting my email, my websites, my storage, my SQL, my Active Directory etc., I'm also in the process of migrating the whole lot to Azure and/or independent hosting. Why? It's just too much hassle these days; I want my down-time to be no longer dictated by my infrastructure. I don't want to have to spend off-work hours making sure my boxes are patched, my disks are raided, my o…

Because apparently you don't need to keep stuff running in Azure patched, I guess?

Microsoft take care of patching Windows VMs, and Exchange is a service, so not your own boxes.

Re: Screw it, I’ll host it myself

#265
post #117
post #85

Earlier quoted context omitted.

The author of this post cites $55/month as his cost. This is wrong. If it takes him, say, two hours a month to maintain (probably conservative) then if you value those hours at $100/hour the actual cost is $255/month. The reality is probably in excess of $1000/month. This only makes sense for people who have an abundance of spare time, and that's pretty rare these days. Free software for DIY hosting like this is "fre…

As a developer, all of the time I spend working on hobby projects (and self-hosting has turned into a hobby) keep me up to date. It's how I learned Kubernetes, it's how I learned Traefik, nginx, and apache before that. It's how I learned how the different packaging and distribution ecosystems work for many different languages and frameworks. I intentionally host and backup some things on AWS, GCloud, and Azure. Other…

I used to think this too, which is why I was self-hosting (I'm the OP of this thread), but as I've got older, and my interests have shifted, along with no longer needing to be at the bleeding edge of my skill-set (I leave that stuff to the younglings these days), I found that managing my own infrastructure felt more like a chore than a hobby, more so if it's a 'production' system and not a 'lab' environment.

Re: Screw it, I’ll host it myself

#266
post #261

The problem I have always had when building elaborate home server setups is the "set it and forget it" nature of the systems I've installed bites me in the ass. Since it's not my full-time job to manage these systems, I'm really not familiar with them the way I might be with the systems I manage at work. These systems cruise along for years, and when something finally does go belly-up, I can't remember how I set it u…

These systems cruise along for years, and when something finally does go belly-up, I can't remember how I set it up in the first place. This happened a few times to me over the years and then I was lucky enough to go on a packer/terraform course. Now everything is scripted and stored in git. A Gitlab job rebuilds the VMs from scratch every two weeks to include the latest bugfixes and updates. It was a lot of work at…

Now you have N problems...

What happens when those images are not available, terraform/packer change APIs, etc?

Re: Screw it, I’ll host it myself

#267

Earlier quoted context omitted.

So I agree with your sentiment, your details are a little off. “it wouldn't be too difficult for them to grab absolutely anything they want. Even disk encryption doesn't save you. You're in a VM, they can watch the memory if they need to.” It would be difficult because you’d have to have host access. VM disk encryption is now tied into an HSM or TPM these days, host access wouldn’t help. As for memory, that is now us…

> It would be difficult because you’d have to have host access. Which AWS has, by definition. > VM disk encryption is now tied into an HSM or TPM these days, host access wouldn’t help. Are you passing all of the data through the TPM? If no: you still need to keep the key in memory somewhere, the TPM is just used for offline storage. If yes: the TPM, and the communication with it, is still under AWS' control. > As for…

"Good to know that AWS employees are either clueless about their own offerings, or deliberately spreading misinformation."

::shrugs:: I don't work for that part of AWS. My opinion came from other experience.

You're not only wrong, but you managed to insult me while being wrong. That's the worst kind of wrong.

If you want some further reading, there is some cool work being done in this space.

https://docs.aws.amazon.com/enclaves/latest/user/nitro-encla...

https://cloud.google.com/blog/products/identity-security/int...

https://azure.microsoft.com/en-us/solutions/confidential-com...

Re: Screw it, I’ll host it myself

#268
post #9

Funny headline, because every time I try to self-host anything important like mail, I learn how deep that field is and how little I know and that I'll probably need many many hours to do everything right and in a secure way (and my mails would still have a higher probability to be classified as spam). Then I think: "Screw it, I'll just use GMail"

I use gmail too but I also have an email from my cheap hosting as a backup. The big problem with gmail is not that Google is reading my email but that this giants can lock you out without a reason and without a right to appeal. I am super salty that Sony banned my PlayStation account(used by my son) for 2 months (I have a Plus subscription paid for 1 year too) without no way for me to see the exact reason (was it a t…

>The big problem with gmail is not that Google is reading my email but that this giants can lock you out without a reason and without a right to appeal.

I also worry about that. What I do is sync gmail with outlook.com. Now I worry that I just doubled my risk of falling victim to a security breach :-)

Re: Screw it, I’ll host it myself

#269
"for purely private use, I wouldn’t opt for AWS even if I had to choose now. I’ll leave it at that"

I will elaborate: I started out with AWS several years ago. I could never work out how they calculated my bill, and had more than one >$100 shocks for hosting my personal services.

I moved to DO and Vultr (stayed with DO for no real reason) and so shut everything down on AWS.

But I still got a $0.50 monthly charge on my credit card. I tried emailing - no response, totally ghosted.

I went through the control panel several times - it is/was a huge mess, obscure by policy obviously - and finally in some far distant corner found something still turned on. I did not understand what it was at the time and can recall no details, but I turned it off with great relief.

A week later I got a email from AWS (!) saying that I had made a error and they had helpfully turned the whatever it was back on...

So I continued to donate $0.50 a month to Amazon until I cancelled the credit card for other reasons. (it would cost $10 for the bank to even think about blocking them)

These days I will crawl over cut glass not to do business with that organised bunch of thieves called Amazon.

Re: Screw it, I’ll host it myself

#270
The article appears to be complaining that free services don’t have good support, so the solution is to spend $55. Major providers do offer support plans. If google/Apple/Microsoft is so critical to your life and data, perhaps it’s worth paying more than zero dollars for?
Post reply on HN