3 ms·
OP here - since there seems to be some interest on the details I will try to answer them in as much detail as possible in a longer blog post. I already wrote ab
by fallenhitokiri 8y ago
OP here - since there seems to be some interest on the details I will try to answer them in as much detail as possible in a longer blog post. I already wrote about the network setup[1]
The server is a Dell Precision T5610 (20 physical cores, 64GB memory, 4 Samsung Pro SSDs and quad gigabit NIC additionally to the internal one) and a QNap TS-531X with Seagate IronWolf drives. I would recommend against using PIs at this point, see other comment[2].
Right now all services are running in docker in a dedicated VM on VMWare Workstation. The server also hosts a full work environment I can RDP and SSH into, depending on what I do, when I am traveling only with my iPad Pro (RDP because my last job involved a lot of Java for which I prefer IntelliJ). At some point I should likely migrate to vSphere, but I had the workstation license already and it was quick to setup.
[1] https://screamingatmyscreen.com/2018/7/building-our-home-and-office-network/ https://screamingatmyscreen.com/2018/7/building-our-home-and...
[2] https://news.ycombinator.com/item?id=17966264 https://news.ycombinator.com/item?id=17966264
- 8fingerlouie 8y agoI'm probably beating a dead horse here with Docker Policies available and all, but i personally don't trust Docker in production. Each Docker image runs it's own stack, and each stack has the potential to contain vulnerabilities. Even with services such as Watchtower ( https://hub.docker.com/r/v2tec/watchtower/ https://hub.docker.com/r/v2tec/watchtower/ ), you're still not safe. Some images are abandoned for years, others are only updated once their "final" product is updated, meaning you could be hosting a handful of vulnerable services without even knowing it. I host all my internet facing stuff on FreeBSD in jails, though Linux with LXC would do just as good. I have one stack to update, and once that's updated, everything else is updated as well.
- fallenhitokiri 8y agoNothing I host is exposed to the Internet but only available locally. When on the road I VPN back home. But generally I agree, for Internet facing services I would likely make a few different decisions than in this case.