32 ms·
Screw it, I’ll host it myself
- throwaway823882 6y agoYou can still have a backup of your files and push them to another provider without self-hosting. It will take up 10x-100x your time to learn and use and maintain these alternatives, versus just taking a regular backup and using a managed provider. It seems like 95% of the adherents to self-hosting do it as a hobby but pretend it's prudence.
- merpnderp 6y agoI always wonder why people don't trust their offsite back-ups to cloud providers. I know they're trying to get away from getting locked out of their data, but what are the odds a burglar steals their computers on the exact same day their cloud provider locks them out because they violated the 'no making fun of ridiculous cloud provider lockout policies' policy? As long as your house burning down and your cloud getting locked don't occur on the same day, you're golden and thus no messing with blue-rays and bank security boxes.
- ClumsyPilot 6y agoI agree, the backup doesn't have to be trusted if you encrypt, and check if it's down. If you have a friend with good internet, you could put a NAS in his house or even give it to him for him to use, just get a quota for some storage.
- bscphil 6y agoI agree. I was especially surprised by: > Every last weekend of the month, I will manually backup all the data to Blu-ray discs. Not once, but twice. One copy goes to a safe storage space at home and the other one ends up at a completely different location. This is one paragraph after mentioning a 2TB+2TB NAS. Even assuming that's RAID1, a standard Blu-ray only stores 50 GB, so you need 40 of those. And then you need another 40 for the other location... every month?? Honestly it's probably cheaper to buy a new 4 TB hard drive every month. If you're a cheapskate like me, backing up your encrypted (e.g. Borg) backups to a cloud provider like Google Drive isn't a bad option. My org provides me with unlimited cloud space, so I have hundreds of encrypted gigs on Google Drive. No reason to think it'll disappear overnight.
- vinw 6y ago> it's probably cheaper to buy a new 4 TB hard drive every month The reason for blurays might be that he's following rule 2 of the 3-2-1 Backup Strategy. 3 backups, 2 different types of storage media, 1 copy off-site. If your house is hit by lightning it could wipe all your magnetic and solid state drives, but optical discs would probably be ok.
- meatmanek 6y agoMost definitions of the 3-2-1 rule count the original data as one of the 3 copies [1][2][3] and don't go as far as to specify that you should be diversified against literal medium type. (Most recommend an external drive or NAS for your second local copy) The "my house was hit by lightning" case is covered pretty well by your 1 offsite backup. 1. https://www.acronis.com/en-us/articles/backup-rule/ https://www.acronis.com/en-us/articles/backup-rule/ 2. https://www.carbonite.com/blog/article/2016/01/what-is-3-2-1-backup https://www.carbonite.com/blog/article/2016/01/what-is-3-2-1... 3. https://www.backblaze.com/blog/the-3-2-1-backup-strategy/ https://www.backblaze.com/blog/the-3-2-1-backup-strategy/
- annoyingnoob 6y agohttps://en.wikipedia.org/wiki/Third-party_doctrine https://en.wikipedia.org/wiki/Third-party_doctrine
- Macha 6y agoUse borg or other encrypted backup tool (Restic is also recommended by others in this thread). rsync.net is my offsite backup. Doesn't matter what anyone demands of them, all they ever see is an encrypted blob.
- thesimon 6y agoI have been using Duplicati, but >Backup archives are mountable as userspace filesystems for easy interactive backup examination and restores (e.g. by using a regular file manager). looks like a really nice feature of borg. Thanks.
- dvdgsng 6y agosidenote: restic can do that too
- pavon 6y agoYou do then need to find somewhere to store an offsite backup of your encryption keys. That said, since those change far less often than your backups, options like a safety deposit box are a more realistic place to store keys than the backups themselves.
- Macha 6y agoYes, borg also has the option of storing them in the repo itself, protected by a passphrase (think encrypted ssh key files). Anyway, my "home burned down rescue bundle" consists of a flash drive with a keepass export of my password vault and encrypted borg repo key / rsync.net ssh keys at the office. Slightly less accessible in this pandemic world, but no safety deposit boxes needed.
- bpye 6y agoYeah I tend to trust B2 for my offsite. I have redundant storage locally with snapshots. That covers up to two disks failing or even someone trying to wipe storage over SMB. The offsite protects against catastrophic failure or theft. I would still like to add in another backup for critical data such as databases, I may use another cloud provider that has geo redundant storage for those.
- Aachen 5y ago> I always wonder why people don't trust their offsite back-ups to cloud providers. Oh I trust them not to delete my encrypted data and that's all that I'd ask. But I still don't have backups on hardware that I don't own: it's super expensive. From the cost of hosted backups, I could buy a hard drive of the same storage space every three months or something. And hard drives live longer than three months. Putting a raspberry pi with a big hard drive at a friend's place is rather power efficient, dead simple to setup if you have any technical knowledge at all, and off-site. Use Restic or something to avoid having to trust your friend or whoever will burglarize the place. They have an Internet connection anyway and where I live, there are no bandwidth caps.
- FunnyLookinHat 6y agoThe diagram alone is more than enough of an argument to dissuade me from giving this a shot right now - it's simply too complicated and too much to manage for the amount of time I can dedicate to it. BUT - I'm really thankful for people who keep posting and sharing these sorts of projects; they're the ones iterating the process for the rest of us who need something a bit more turn-key. I'm excited to see this eventually result in something like the following: - Standard / Easy to update containerized setup. - Out of the box multi-location syncs (e.g. home, VPS, etc.) - Takes 5 minutes to configure/add new locations I want this to be as easy as adding a new AP to my mesh wifi system at home: plug it in, open the app, name the AP, and click "Done". (Edit - formatting)
- gsreenivas 6y agocheck out Helm - thehelm.com
- merb 6y agojust use k3s + (restic + velero [backup]) it's soo much easier you can basically install everything with the same tooling and update everything with the same tooling. if something breaks, bam you can just restore the whole cluster with velero (including local volumes)
- imwillofficial 6y agoI used Cloudron.io for most of the above. Check them out. Most polished self hosting experience by far.
- babelfish 6y agoAnd they have a good 'eject' option.
- SkipperCat 6y agoWe always have this debate at work. Do we build the system ourselves or do we purchase a product? On prem Prometheus or push everything to DataDog? I'm always a fan of building things myself because I like building things, but my company compares engineering time vs product cost.
- nautilus12 6y agoFor personal use it seems I agree with other comments that it seems like alot of work. But in a corporate setting it could be useful, wonder if these types of applications (NextCloud) is how the cloud gets broken up eventually.
- mixxit 6y agoi tried to use nextcloud for a good two years the mobile app is crucial to me and its search and performance let me down when the car broke down and the time i needed it at the most at the hospital i wish it was the not this way i really do
- gowld 6y agoDoes the web app not work on mobile?
- 12ian34 6y agoI'm curious as to for how long you've been using this setup specifically in regard to Nextcloud, and how many and what volume of files you store in it? I've set up a few Nextcloud instances in the last 2 years on Digital Ocean VPSs and Raspberry Pis and I ran into so many problems and difficulties which scaled with the quantity and size of files I hosted on it. I took care in setting up everything to a relatively solid standard (memcache etc.), but I found Nextcloud to be so unreliable for syncing particularly with the official Android and Linux clients. Plus, there was the whole botched version 20 upgrade. I find Nextcloud tries to solve too many problems turning it into a bloated mess even for a moderately experienced user. For file storage only, I've found Syncthing on a Raspberry Pi at home syncing over Zerotier (for when I'm not at home) to be a much more robust, user-friendly and scalable solution, despite it syncing whole folders only.
- thedanbob 6y agoWhen I was picking a self-hosted Dropbox alternative, I ended up going with Seafile rather than Nextcloud since it was a lot more focused (just file sync) and people said it was much faster. It's got a few rough edges but the core functionality has been rock solid. Granted, I've only had about 100 GB max stored in it.
- bpye 6y agoI didn’t realise Seafile Pro was free for up to 3 users. I had previously looked but gave up as no self hosted solution was really comparable to OneDrive or Dropbox.
- GordonS 5y agoI've been using Seafile for several years, and highly recommend it. For the past couple of years, I've had it running in Docker on a cheap Azure VM, backed by blob storage. I've got around 2TB in there, and it all works marvellously.
- andrejserafim 6y agoSyncthing is great! Are you using zerotier for transport security. Or does it improve speed as well? Off-site syncs are far too slow for me. Luckily, it's very rare that I have to do them.
- planb 6y agoFunny headline, because every time I try to self-host anything important like mail, I learn how deep that field is and how little I know and that I'll probably need many many hours to do everything right and in a secure way (and my mails would still have a higher probability to be classified as spam). Then I think: "Screw it, I'll just use GMail"
- syntheticnature 6y agoInterestingly, it doesn't look like the author is self-hosting email. I know mail-in-a-box exists, but even with that I find it's worth the peace of mind to pay someone else for mail hosting.
- SavantIdiot 6y agoSame here. Over the past 20 years (25?) I've tried numerous times to self-host email and the issues I had with spam and blacklisting were too involved for me to resolve, and only got deeper. Definitely not something to attempt casually.
- imwillofficial 6y agoNo need to self host email, just use your own domain. That way if a provider gives you lip, you move on. It’s the email address itself that is valuable, the emails can be backed up.
- SavantIdiot 6y agoThat's true. I already host my domains with the requisite DKIM/SPF CNAME entries, and I supposed I could just export the mailboxes periodically.
- TheRealDunkirk 6y agoI ran my own email server on my own domain for years. You're right, it's kind of its own special nightmare to integrate all the parts of a comprehensive email system (I eventually started using Zimbra's free server software because of it), but spam effectively killed being able to self-host more. Even if you setup SPF and DKIM and all the rest, you'll find yourself getting blackholed anyway because you're NOT Google or Apple or Microsoft. It's not like I even sent email in bulk either. It was just my normal, personal account. But getting OFF blackhole lists became enough work that I had to route my mail through Gmail anyway, so I just gave up self-hosting entirely. That was, like, 7 or 8 years ago, though, so maybe things are different now, but I doubt it. I expect it to only have gotten worse.
- JumpCrisscross 6y agoI successfully extricated myself from Gmail to ProtonMail, only to be getting dragged back to Office 365 due to ProtonMail not having a working calendar and FastMail not supporting calendar sharing (to non-FastMail users) or delegation.
- thegeekbin 6y agoProtonMail Calendar works fine now... give it a shot?
- JumpCrisscross 6y ago> ProtonMail Calendar works fine now It's fine for simple use, but without the ability to create calendar invitations it's far from the competition. (To say nothing of sharing e.g. free/busy with my work calendar or delegation.)
- clairity 6y agoyah, microsoft won office productivity 2 decades ago with exchange and outlook (and owa), not just excel and word. the integration between email, calendar, contacts, documents, and access control is still unmatched, certainly not by google's hodgepodge of web apps. proton is working on calendaring but it still has a long ways to go.
- TheRealDunkirk 6y ago> exchange and outlook (and owa)... the integration between email, calendar, contacts, documents, and access control is still unmatched So we're just going to pretend that iCloud doesn't exist, then? Is that it?
- clairity 6y agonope, icloud is great at both losing and duplicating data reliably.
- louwrentius 6y agoI like the article and I agree with the sentiment. I think that self-hosting can be quite a bit of effort, but a tool like Ansible makes it so much easier. Whatever you choose to do, the most important thing is that you create data(base) backups and store those in an environment that you can control at all times. There needs to be a viable exit strategy, just a backup is not enough if it takes more time to restore operations/service than is viable from a business perspective. Perform at least a risk analysis, whatever you choose, make it a conscious, deliberate decision.
- 14TheLamb 6y agoBut what will you do if people aren't telling you exactly how to run your life and your setup? I certainly appreciate the effort and will be digging into this. I'm so sick of the tyranny. I've started my own 'disconnect' plan, and this is giving me a lot of ideas. I've already deleted Facebook, Amazon (that was a hard one), and well on my way to independence. Google is next, and like another commenter I'm using Proton mail now exclusively. Kudos for your efforts to help those of us that are really struggling right now - much appreciated.
- lawwantsin17 6y agoAre you hosting it yourself or are you hosting it with various cloud and Paas companies that just aren't Amazon? Because I read the article and it's the definitely the later. Nice try. Bad headline.
- bndw 6y agoIMO you can get 90% of the utility here (owning your data) with just the NAS and rsync. 1. Don't feed the FAANG 2. Store your SoR media, notes, documents on your own NAS 3. Automate a backup of the NAS, preferably both on and off site (I use rsync from a pi + large disk + cloud blob storage)
- varispeed 6y agore 3 Restic is pretty good as you get your data encrypted locally, so it can be used over untrusted storage facilities.
- andrei_says_ 6y agoSynology backs up beautifully to the cloud.
- ClumsyPilot 6y agoI second this, either get a Synology/Qnap NAS or take an old PC with a couple drives and install OpenMediaVault/Freenas/Unraid. All of these platforms have out-of-the-box solutions that mirror most cloud services. I found homelab redit to be great. If you get the off-the shelf NAS, get one with at least 2GB of ram! Synology is particularly notorious for selling NAS with 512MB(WTF?!) of ram, and then when you try to run a few applications it grinds to a halt.
- qznc 6y agoNAS fails for smartphone integration. Photos should auto upload. Calendar, todos, and contacts need to show up in the usual apps. It needs to be available from remote.
- squarefoot 6y agoSyncthing may be used to sync remotely the relevant directories. It's multiplatform and has a Android app too (still not iOS though). https://syncthing.net/ https://syncthing.net/
- nicbou 6y ago
- napsterbr 6y ago> I’m living in Germany, so the obvious choice was to spin up my instances in Vultr‘s* data center in Frankfurt, as ping is the lowest to that center for me. The author is probably aware of this, but just in case they aren't: Hetzner is an amazing company with two or three datacenters in Germany. I don't remember if any of them are in Frankfurt, but given they offer VPSs and beefy dedicated machines, I'd be fine trading a couple milliseconds for this flexibility (and overall better pricing, even if Vultr's isn't that expensive as well).
- bscphil 6y agoI don't know what qualifies as "amazing company" in your eyes (they're certainly cheap for what you get), but my experience was certainly very bad: I rented a VPS from them experimentally for a month, then left to go on vacation thinking I had cancelled it, but I had not. They left it running for another month that I hadn't paid for, and then sent the bill for the extra month to collections, so that's presumably affecting my credit score now. Sending a bill for a recurring service to collections rather than just canceling the service is trash-tier company behavior, IMO. I strongly recommend against using Hetzner.
- napsterbr 6y agoI can see why that's a bad experience for you, but IMO Hetzner did the right thing here. What if I forget to pay my AWS bill for a week and, because of that, all my resources get deleted? IIRC AWS will inactivate your account after 3 months without payment, so the same thing would've happened there. 3 months is a nice trade off between "forgot to pay my bills" and "no longer use the service". ETA: for sure it sucks they sent the bill to collection. Uncalled for, they could've attempted to settle directly with you first.
- 0xbkt 6y agoAgreed. Hetzner is very strict about not leaving a penny of theirs wasted/delayed without compensation. I know a couple friends here in Turkey who were contacted by a local collection agency for late settlement and were brought up with legal proceeding if they're not settling it soon. Aware of this, I started to never ever /forget/ about paying any of my bills on time.
- imwillofficial 6y agoOk, I’m SUPER into self hosting, but this article? No way. 1) Duck out isn’t a thing, just stop it. 2) Half the articles cited as examples of corporate abuse were later revealed to be mistakes by the user or easily avoidable pitfalls. 3) Self hosting still requires trust (software you’re running, DNS, domains, ISP, etc...) The line of who to trust and how far is a tough one to answer, even for the informed. How I solved it: 1) I use well vetted cloud services for things that are difficult/impossible to self host or have a low impact if lost. (Email, domains, github, etc...) 2) I self host things that are absolutely critical with cloud backups. (Files, Photos, code, notes, etc..)
- ziml77 6y agoI am perpetually confused about why people think that self-hosting on a VPS solves their privacy and security problems. While I'm sure there are controls in place at reputable VPS providers, it wouldn't be too difficult for them to grab absolutely anything they want. Even disk encryption doesn't save you. You're in a VM, they can watch the memory if they need to. Using a VPS can also make you more identifiable. Your traffic isn't as easily lost in the noise. The worst thing that I know of people doing is using a VPS for VPN tunneling. While it can have its uses, privacy certainly isn't one of them. You're the only one connecting into it and the only traffic coming out of it.
- judge2020 6y agoA setup that probably works is vps -> tor -> vpn or some other order of these three, but I couldn't find any sort of blog that detailed setting up something like this so I imagine very few people are doing it.
- lisper 6y agoVPS doesn't solve privacy and security, it solves getting locked out of your account because some algorithm decided you were peddling child porn. If you want privacy and security and you don't trust your provider, then you have to build your own hardware and compile everything you run on it from vetted source, including your kernel. You can do it, but most people decide that on balance its better to trust someone.
- asattarmd 6y agoThe most valuable thing for me is my photo library. All of them are currently in Google Photos. Is there any easy way to backup just that? I don’t care about my personal email, tasks, calendar etc. It’s just the thought of losing my photos scares me.
- pjerem 6y agohttps://takeout.google.com/ https://takeout.google.com/ is exactly what you want. Deselect all, check "Google Photos", click Next, chose your archive format, confirm. It'll take some time but at the end of the process, you got a nice zip with all your Photos in original quality.
- mcjiggerlog 6y agoYeah, https://github.com/gilesknap/gphotos-sync https://github.com/gilesknap/gphotos-sync. There's a decent guide here: https://ubuntu.com/blog/safely-backup-google-photos https://ubuntu.com/blog/safely-backup-google-photos. I run this every night on a raspberry pi, syncing them to my local NAS which is in turn backed up to cloud storage.
- TimBurr 6y agoI mentioned it in a different comment, but take a look at Syncthing. It does mesh-style backup to synchronize a folder between multiple machines. That provides robustness against hard drive or PC failures, and it's easy to add an offsite node for extra confidence. You can use Takeout to bulk-download photos: https://support.google.com/accounts/answer/9666875?hl=en https://support.google.com/accounts/answer/9666875?hl=en I don't know if you can automate syncing Google Photos to a local disk. Wouldn't be surprised if there was. (edit: Wow. Lots of people wanting to help! I wasn't expecting two sibling responses.)
- asattarmd 6y agoI found a solution: Use Photos (iCloud photos) along with Google Photos since I already use an iPhone. Thanks for the comments, but I believe this is the easiest.
- gsreenivas 6y ago
- jedberg 6y agoWhere does he host his email? It doesn't say. Also, his website is very slow, probably because he's not using a CDN. A noble goal, but it has an impact on credibility. The slow website makes me feel like he doesn't care about user experience, which makes me assume that is true for his whole setup, and turns me off from even considering it.
- imwillofficial 6y agoThat’s a massive jump to make when he is probably being beaten to hell by HN right now. That’s not a reasonable chain of expectation. Reevaluate your logic.
- jedberg 6y agoIn 2021, HN doesn't make that much traffic. Any decently built website should be able to handle it, if the owner cares about the user experience.
- imwillofficial 6y ago"HN doesn't make that much traffic" Cite your sources, that claim sounds made up. Your inference that if somebody doesn't use a CDN or have acceptable load times for you, that they don't care about user experience, and so their opinion on self hosting is not worth listening to is absurd.
- jedberg 6y agoWell here is a link about someone who made the front page in January: https://nicklafferty.com/blog/what-happens-when-you-re-on-the-front-page-of-hacker-news/ https://nicklafferty.com/blog/what-happens-when-you-re-on-th... They said they got 18,000 hits in one day. That's a tiny amount of traffic for any decent static website (which this one that we are talking about is). Even assuming they got all that traffic in one hour, that's only 5 requests per second.
- 5y ago
- TimBurr 6y agoDepending on what you need, a NAS + Syncthing is much simpler than the linked article. Building a PC isn't hard, and keeps prices down. These days, a RPi 4+2 USB HDDs would run circles around the motherboard on my NAS. Syncthing is a great continuous backup solution. I use ~/NOTES as a scratchpad, and it updates automatically between my various computers. It gives you pretty granular control over shares, and I back up critical stuff to a cloud provider. That said, there's no calendar/email/notes. XigmaNAS is built on FreeBSD, and will happily run NextCloud or a photo gallery or whatever.
- clircle 6y agoSyncthing is great, but the lack of first party iOS client drove me to Nextcloud.
- EGreg 6y agoTime to update this news story a month later with more breaches and with just the names changed: https://qbix.com/blog/2021/01/25/no-way-to-prevent-this-says-only-industry-where-this-regularly-happens/ https://qbix.com/blog/2021/01/25/no-way-to-prevent-this-says...
- novok 6y agoIf you really want control, what matters more is you having control of your own domain and encrypting what doesn't need to be public, such as backups and notes. Managing a self hosted system is often more expensive and more time consuming, and often those self hosted services store unencrypted versions of your data. But now you have to maintain the security of it yourself, usually worse than professional services, and your still one subpoena or hack away from it being exposed. In the end you are still just as vulnerable getting booted off with VPSs like you are with google, but with domain control you can still switch hosts without losing your address, and you usually have customer support.
- llaolleh 6y agoI really love the idea of self-hosting, but man, you have to go through 9 layers of configuration hell and come back out alive. It's not necessarily fun programming - more of changing variables and running commands, which you might get wrong anyway. I wonder if there's a viable business model for this. Automate the setup through scripts and process automation for any provider. You pay a one time fee + a reasonable amount for maintenance and for resilience built in. I would pay for it if the price is reasonable.
- thestepafter 6y agoSo how much would you pay?
- turtlebits 6y agoThis is what Kubernetes is for. Personally, I run k3s, but setup and config looks like this - 1. stand up a cluster. (two commands, install docker, install k3s) 2. apply yaml files (kubectl apply -f .) I run 6 services/"apps" on 2 OVH servers ($6.70/mo)
- pjc50 6y agoI've had my own domain for something like 22 years now, but it's been a long time since I used it to actually host stuff. Email in particular I gave up over a decade ago and pointed at a hosting provider. I still read that email with mutt over ssh. I suppose I should have another go at a blog.
- johnbrodie 6y agoI had the same thought as the title of the article go through my head, but we ended up with a simpler setup as I wanted something I don't have to constantly mess with: * Put together an overbuilt NAS box running ZFS On Linux * Simple docker-compose file for all services * Backups through borgmatic (via ZFS snapshots) * Auto-updates through watchtower * Punted on email and use FastMail, switched to our own domain from gmail Services we run include: * PhotoPrism for semi-Google Photos functionality * Nextcloud and Collabora for file sync, sharing * Kodi for home media * Tiddlywiki * DDNS through Gandi since we're on a dynamic IP * PiHole for some ad/privacy protection * Robocert for SSL * Nginx to reverse proxy everything It wasn't _easy_ to set up, but in a year, any given week I typically spend 0 hours dealing with it. No problem that _has_ cropped up has taken more than a few minutes to fix, mostly around docker networking and auto-restarting containers after Watchtower auto-updates them, a problem I've since fixed. This setup seems way easier than k3s or some other recommendations, doesn't require much new knowledge, and is as portable as I need it to be. If needed I could plop the docker-compose on a new machine, change some mount points, and largely be up and running again quickly. It's let us switch to "deGoogled" phones and unplug from almost every hosted service we used to use.
- jeff-99 5y agoI have almost the same setup and it's working like a charm. Was still looking into a backup solution so I'll take a look into borgmatic
- codehawke 6y agoI created codehawke.com architecture from scratch to avoid hosting my content on other people's platforms. I make way more money than with platforms like Udemy. I think we should all be moving away from other people's platforms and tools.
- haolez 6y agoThe author treats his personal life as a job, with productivity tools and benchmarks. Whatever works for you, but I couldn't live like that.
- nirav72 6y agoFor some of us, we turn it into a hobby. Only difference is that the technical knowledge and experience gained at work, can also be applied at home. (without a lot of restrictions).
- haolez 6y agoWhat I meant is that I need some time to _not_ be productive. Like, actively not being productive. Literally wasting time for the sake of getting some peace of mind and true relaxation. If your personal life is filled with productivity tools and optimizations, at what time in your daily life your are _not_ worried about productivity? If this time is zero, I think it's kind of sad and maybe even unhealthy. It's just my opinion, of course :)
- cinericius 6y agoI agree with you on the importance of non-productive time but I've found having my own infrastructure makes my life smoother day to day in exchange for some upfront cost. It's a tricky balance, and as many other commenters have mentioned that initial cost can end up not being so initial - though I think most people who engage in this 'hobby' generally find both the process and the product rewarding.
- shockeychap 6y ago"A drinking game recommendation (careful, it may and probably will lead to alcoholism): take a shot every time you find out how someone’s data has been locked and their business was jeopardized because they didn’t own, or at least back up their data." That one put a smile on my face.
- yoz-y 6y agoYou could play a reverse game of every time somebody lost all of their data (or more probably, photos) because they owned everything and _thought_ they had backups too. (e.g.: when the OVH datacenter burned down)
- Sphax 6y agoI'm willing to bet you could run all these services on a single VPS. Having to manage 6 different hosts is going to be a pain in the ass, even if you use something like ansible. As far as backups, I don't understand why the author doesn't just encrypt them and send them to a cloud storage; it's what I'm doing personally with restic and it's not even expensive.
- dvdgsng 6y agoSame here, I host more than that on a single server at home for the family. Encrypted restic backups to Backblaze are so cheap, there's no reason not to do it.
- hedora 6y agoI’ve found the following setup works well. It’s simpler, but less featureful: Website is a git repo stored on a nas, and backed up. (GitHub would also work; private repos were scarce when I set this up). It’s published with “s3 sync”, and sits behind a cheap cdn. Desktop is backed up to NAS (via NFS; would use syncthing if I was setting this up again. Previously, I used Unison, which confused some other users of the desktop, but I like it anyway.) NAS uses synology’s client side encrypted HyperBackup to B2. Calendar and contacts are on the nas, using baikal, which runs in a docker image on the synology. My phone is fine with periodic access to the contacts and calendar server, so this sits behind the firewall, and is not accessible via the internet. Total monthly cost is pennies, not counting domain names, or the B2 backup data. The main problem is that all the data will be compromised if the NAS is stolen. I’m looking for a good solution to that next.
- habibur 6y agoHosting my own too. There's gmail as backup. But host my mail server, webmail, imap, smtp everthing. Blocking spam isn't that problem. But making sure your mail goes to the receiver's inbox is. You can block 90% of the spam by using only reverse DNS lookup -- doesn't match? Reject. 90% of the remaining can blocked using DKIM, SPF checks. No need for ip black hole check or spamassassin training. The benefit : I can block a sender or his domain in a single click from webmail. Couldn't do that on gmail.
- mfollert 6y ago> I can block a sender or his domain in a single click from webmail. Couldn't do that on gmail. Omg, yes, I really miss such a feature.
- megous 6y agoFlexibility of self-hosted mail is very nice. At the moment I don't filter on the server at all, because I think anyone should be able to reach me no matter how dumb the mail setup is. Send me mail by manually typing to a TCP:25 connection from a residential or mobile IP, I don't care. No DNS checks, etc. My postfix config is very permisive, only relaying is disabled. I filter using bogofilter on emails delivered to my public addresses. Private randomly generated aliases don't get filtered at all (only the sender knows them, so I just disable the address if it gets abused). It works nicely, especially the private alias part. I have alias/mailbox table in PostgreSQL DB, but don't bother with trying to connect postfix directly to the DB. I just dump the tables to the postmap files on each change. It's infinitely more performant and reliable, which is what this has to be. I can also dump the DB to my MUA's config, and have it rewrite all the random addresses into something readable.
- whalesalad 6y agoI fully support this as long as you can click a button and deploy a new instance when one dies.
- jdroe1211 6y agoWow, what a disgusting indulgent statement. Period. Much love. Ugh.
- mattowen_uk 6y agoY'know what, Although I'm currently self hosting my email, my websites, my storage, my SQL, my Active Directory etc., I'm also in the process of migrating the whole lot to Azure and/or independent hosting. Why? It's just too much hassle these days; I want my down-time to be no longer dictated by my infrastructure. I don't want to have to spend off-work hours making sure my boxes are patched, my disks are raided, my offsite-backups are scheduled, and my web/email services are running. I just want it all to work, and when it doesn't, I want to be able to complain to someone else and make it their problem to fix it. For my data, I'll probably still have an on-site backup, but everything else can just live in the cloud, and I'll start sleeping better, due to less stress about keeping it all secure and running.
- api 6y agoThe author of this post cites $55/month as his cost. This is wrong. If it takes him, say, two hours a month to maintain (probably conservative) then if you value those hours at $100/hour the actual cost is $255/month. The reality is probably in excess of $1000/month. This only makes sense for people who have an abundance of spare time, and that's pretty rare these days. Free software for DIY hosting like this is "free as in piano." Like a huge piano sitting on the street with a sign that says "free piano," it is actually not free at all when you factor in the hidden costs.
- CharlesW 6y ago"Free as in free puppy" is my other favorite metaphor. Free software is a gift to the word, but IMO it's important not to undervalue the time and expertise of operationalizing it.
- thih9 6y agoIt's worth remembering that you can get an expensive puppy too. I.e. choosing proprietary software doesn't mean that time and expertise won't be required. Recent previous discussion at: https://news.ycombinator.com/item?id=26672009 https://news.ycombinator.com/item?id=26672009 .
- 6y ago
- annoyingnoob 6y agoThe most chilling reason for me to self-host is the third-party doctrine. https://en.wikipedia.org/wiki/Third-party_doctrine https://en.wikipedia.org/wiki/Third-party_doctrine You don't really own any of your cloud data, even if it feels like it. If you want to own your data then it needs to reside on private computers in private spaces - though that does not preclude you from sharing but you lose control of what you share.
- gsreenivas 6y agoThis is a key reason for why I started Helm - thehelm.com. There's a lot of talk here about the hassle of self-hosting and while many HN folks are perfectly capable of running their own servers/services, it can be very time consuming. We take away the hassle and provide the benefits of self-hosting at home.
- abraae 6y agoI don't know anything about helm, but your promotional comments in here are getting a little shrill. I feel less inclined to investigate it tbh.
- deleted 5y ago[deleted]
- 2ion 6y agoI don't self-host everything, for me it's enough if I can take out all my data. I have all my cloud hosted things mirror via rclone to local storage. So I'll gladly use git, IMAP, CalDav, CardDAV as a service but I'll have my local hot mirror and cold backups ready any time. Tools are readily available: * git is git and clones * IMAP gets pulled via mbsync * CalDAV, CardDAV get pulled via akonadi and exported to flat files from there * Remote SSH/SFTP accessible storage gets pulled using rsync * Other remotes get pulled using rclone and some more.
- NicoJuicy 6y agoI've got 4 servers and an app that monitors everything. Daily backup is 30 days retention. Only had to setup once. Weirdly enough, i don't have any maintenance. When I log in to create a new site, i see all the stats too. It would cost me at least 18€*30 in the cloud ( amount of sites). I'm 100% sure self hiding for me is a lot cheaper. I use Gmail and a box account too fyi. But i don't consider that "the cloud", it's a service that i use. Not something to deploy my own development on. Ps. My uptime is better than a lot of services that is the cloud.
- m00x 6y agoSo, what happens if Vultr locks him out? Sounds like an even worse situation.
- cube00 6y agoAt least he has a fighting chance to talk to a human at a local company. You won't get that from Google. Even if you pay for Google One you can still get blown off with "I've already given you all the information I have" (nothing) because telling you why you actually got locked out opens them up to a discussion they are not interested in having.
- danbruder 6y agoTheres an opportunity here for someone to build a "platform" that makes this all plug-n-play; like what the apple/google app stores have done but where the end user has control. Something along the lines of someone buys some hardware with this platform on it and gets a gui that lets me install "apps" on top of it. Personally, I've got a home setup that is on its way to what the op has; but I think there's demand from non-techy folks to get off the big co's apps and onto privacy focused ones that they control.
- paulryanrogers 6y agoLike Sandstorm?
- ryukafalz 6y agoYup, the sibling comments mention a few alternatives (FreedomBox and Yunohost) but Sandstorm is really the only one I've ever used that makes me confident in the state of the system long-term. Let me elaborate on that. FreedomBox and Yunohost use more traditional software installation mechanisms; they'll install packages, run scripts, etc. They just add (sometimes very nice) UI around it. While that's great for some things, after a while things can get a bit messy. For example: what about when a package installation fails for some reason? Or one of the configuration scripts fails? Well, you're stuck logging in and troubleshooting, which isn't super fun (and might be intractable for less technical users). Sandstorm, though? Everything is sandboxed and isolated from the rest of the system. Everything. Backing up or restoring an instance of an app is a few clicks in a web interface. Sandstorm handles auth so the app doesn't have to... etc etc. This has its downsides, namely that apps that aren't written with this sort of usage in mind might not fit in as well. But for those that are, it's by far the best experience I've had. I have Yunohost and FreedomBox servers in varying states of disrepair, but my Sandstorm server keeps chugging along. Big fan.
- ocdtrekkie 6y ago:) Always glad to see Sandstorm fans here. FWIW, there are places Sandstorm could improve here. Probably the biggest one for me is that Sandstorm backups do not happen automatically in the managed space. (You could automatically back up your Sandstorm server with another utility, and you can manually backup/restore individual grains in the web UI, but there isn't yet a really clean integrated way to restore grains inside Sandstorm.) But if this is the one thing you have to figure out outside of Sandstorm itself, that's not too bad (or unusual for many server applications). Also, the parent suggests being able to offer a hardware box good-to-go, and I'd like Sandstorm to have that, or at least, a full distro release, where you do not have to worry about the server OS at all. It's something we've talked about quite a bit.
- buffalobuffalo 6y agoI've recently thought this would make a great business model. You set up a service where you deploy open source tools like email, picture storage, etc to run on aws lambdas for people. All they would need to supply is a domain name (via oauth access to dns providers) and an aws account. For a single user, the app's costs would probably be under a dollar for a year. They pay you a one time setup fee, and a maintenance fee only if they want to receive updates. Configure nightly backups for them, etc. I'd definitely pay if this existed already.
- bjt2n3904 6y agoI've been running Nextcloud myself, and I love it. I've been looking to expand my infrastructure even further -- the synology NAS are wonderful. The biggest thing is that I don't think this matters anymore. Google, CloudFlare, and Amazon rule the internet. If they don't want you to be on the internet, it doesn't matter how resilient your infrastructure is. Especially when it comes to critical things, like email.
- hoprocker 6y agoI love it. Some of these solutions are things I looked into during the early days of Android, before Google had cemented hegemony on so many things. Namely, Subsonic and K-9 Mail were some early contenders that I remember, although both quite clunky at that point (Subsonic very much had the patina of a one good developer, but no UI specialist, team).
- grep_name 6y agoI tried to have a setup similar to this during covid but ended up with a bit of a mess. What I wanted was a home server that used X forwarding to forward services to my VPS, which also had some images running in a docker-compose stack that I wanted to have more robust uptime than my home server. I ended up being unable to get traefik to pick up on the x-forwarded ports, and ran into SSL certification issues that seemed insurmountable wrt hosting jellyfin this way. Does anyone here use a hybrid home-server / VPS setup like this and know of a better setup? I prefer x port forwarding because I move about once a year and don't always have access to router settings
- megous 6y agoYes, I use wireguard to link VPS with an array of computers in my home via point to point tunnels. This solves the "my home IP not being completely static" problem, because wg handles roaming quite gracefully. And then I just use either DNAT or nginx reverse proxy to proxy https to some http ports at home, depending on the service.
- grep_name 6y agoInteresting! I've never used wireguard before. When you link it with the VPS, is it able to behave as if ports from your home network are running natively on the VPS? I'll look into using DNAT/nginx, but I really do like having everything in a format where all the configuration is self contained in code and can be spun up / down easily, and I'm not sure if I can accomplish that using those tools
- megous 6y agoYou'll see a wireguard network interface on all the connected devices, and you can configure some private address subnet on it, like 192.168.1.0/24 and give the devices some addresses from this range. Then you can just talk between any of the devices via this subnet. Wireguard will securely tunnel the traffic. https://www.wireguard.com/ https://www.wireguard.com/ DNAT is just a concept https://en.wikipedia.org/wiki/Network_address_translation https://en.wikipedia.org/wiki/Network_address_translation You can set it up using iptables or nftables. You don't need to use nginx, use http reverse proxy you know.
- BlueTemplar 6y agoA year ago, I tried to get into it, but : - My ISP and Pihole didn't have proper IPv6 support. - Even worse, Pihole requires phoning home to Github for updates... which I wanted to block with Pihole! So I've shelved this idea for now...
- RcouF1uZ4gsC 6y ago> Every last weekend of the month, I will manually backup all the data to Blu-ray discs. Not once, but twice. One copy goes to a safe storage space at home and the other one ends up at a completely different location. The author has a lot more patience than I do. From their description of the NAS, they have at least 2TB capacity. At 50 GB per disk that is 40 Blu-Ray discs to reach 2TB and 80 discs to do it twice. There is no way I would spend a weekend very month burning and verifying 80 Blu-ray discs.
- clircle 6y agoI have a similar setup, but I'm using a raspberry pi. Does anyone know a good iOS client for Nextcloud Music?
- akho 6y agoVultr seems entirely unnecessary in this picture (but the referral dollars probably help). They are just hosting stuff for themselves, right? The Synology can do all that (through VPN for the on-the-go devices). Separate VPSes for things like a 1-user Monica instance are insane.
- regularfry 6y agoDepends how reliable the home internet connection is. Pushing it out to a VPS means you can carry on regardless over 4G if the broadband flakes out.
- sandreas 6y agoOne thing that would interest me: What about Ransomware? If everything is connected and synced, how to prevent getting everything encrypted before it is too late? For me encrypted FreeNAS with readonly ZFS-Snapshots have been a good solution for this.
- theandrewbailey 6y agoDelete everything on synced devices and restore from offline backups.
- ballerburg9006 6y agoDefinitively the wrong approach. I wrote this on another board: > Everyone has 100Mbit lines now, a lot of people have gigabit fiber internet at home. > You can get a Cortex-A55 TV Box for $30, plug in your old SSD drive via USB 3.0 with > a $3 adapter, install Linux and you are ready to go. It consumes virtually no power. > The processing speed and disk speed is incredible. Often the ping is lower than in a > datacenter. This is not even the future of hosting. It has been around for quite some > time. It is totally superior to any mid-range server. There literally are only advantages. Pair this with Yunohost (via Docker). Yunohost is like an appstore for Linux servers. Easy 1-click setups for Nginx, Xampp, Postfix, Dovecot etc. that average people can do and understand. You can still use the TVbox as a media center, even run Libreoffice on it and Blender like a small mini PC that has "poor but good enough" performance for most everyday tasks. Also games via Retroarch. Sounds too awesome to be true? Yes, it is not quite true yet. You can do all this, but you still need to be tech savvy to step through it. And the media-center part is still questionable, because video drivers (the ones that work with hardware video acceleration) are bugged on most SOCs. Games work though, just not HD videos.
- _carbyau_ 6y agoMy HTPC gets parts handed down from my gaming PC. I want to leave it "always on" anyway and so I was thinking of yunohost but you've now confirmed my path. Thanks!
- BrandoElFollito 6y agoI host everything myself, except mail. I just do not trust myself to followup with each blacklist when my IP gets there.
- trbfred 6y agoTried the same some time ago. While setup is fun, maintenance etc. is mostly underestimated. Following Murphy's law, things mostly break in uncomfortable times (deadlines, etc.). My (current) strategy: Do without the "last functionality" and stick with boring, local software/approaches. Not everything needs to be synced to / accessible from any device -- at least for me... One well backed-up machine, a few online services (e-mail, github for collaboration, ...) and long-proven applications like Photos.app. Something close to the situation 15 yrs before?
- karmakaze 6y agoI like the article and many of the recommendations (and some others to look up). I do host some of these things but likely never all of them. The post wasn't entirely clear on whether it was primarily privacy motivated or availability. If it's not about strict privacy, it's far easier to use whatever is convenient and still allows you to stream-replicate the data. For Gmail, I send a copy for accessibility outside of Gmail. The post itself includes offsite-backup so you could just start there if you consider your primary use site to be the 'onsite'.
- gigatexal 6y ago"Is it worth the time and hassle? Only you can answer that for yourself." No. Absolutley not. The little sys admin work I have to do at work is all that I want to. I trust Apple and Google with all my stuff -- icloud storage, passwords, Google for email, etc. It just works, and I can move on with my life and focus on things of value to me instead of worrying about an upgrade blowing things up, security patching, backups, etc.
- cdeutsch 5y agoExactly. "If I had to guess, I would say ~40 hours" That's just the tip of the iceberg if you're going to maintain this for years upon years. No thanks
- dervjd 6y agoI'm doing something similar with a NUC that I colocated. $27/month for a gigabit port + 5 IPv4 addresses, and it's far more powerful than any VPS I could get for the same amount of money. It was a little bit of work to set it up initially, but now I maybe spend 30 minutes a month making sure things are updated. Hosting my own wiki, DNS over HTTPS server, Matomo analytics, and a few other random services.
- mxuribe 6y agoWow, maybe my understanding of colocation costs is outdated...but $27/month sounds crazy inexpensive! May i ask @dervjd where/from which colo provider you are getting such costs???
- boring_twenties 6y agoI, too, would love to know where you're getting those colo costs. That seems too good to be true. A reputable provider near me offers 1U with 100Mbps for $75/mo. That's with one power outlet, a second one costs another $35/mo. :(
- divyenduz 6y agoDoing something very similar, hosting a lot of things on a Raspberry Pi 4 with 400 GB SD card. Dockerizing most things https://github.com/divyenduz/dev-infrastructure https://github.com/divyenduz/dev-infrastructure Not as easy though, I still need to figure backup strategy and everything. My goal is to eventually remove photos, and almost everything hosted entirely really.
- haskal 6y agoWhat kind of SD card are you using? How many writes/transfer speed? The fact that the card can die on you and lose 400 GB of data gives me nightmares. I got a Rock Pi recently and it supports M.2 slot and eMMC that goes up to 64 GB, this makes me less nervous.
- boardwaalk 6y agoI have a simple script that tars and gpg encrypts specific directories nightly. It’ll also reap backups in a sane way (only keep one per week for the last month, one per month for the last year, etc). And it’ll stop/start services/containers while backing up as needed. Then I distribute the backups to various devices using Syncthing. I’ve been thinking about also having an off-site backup (for a house fire, electrical storm when everything is plugged in, etc), but that might be slightly paranoid.
- calltrak 6y agoI hear ya buddy! The internet was supposed to be decentralized and democratic. Why does everybody seem to think the "cloud" is AWS, Microsoft and Google . That's completely nuts. Lets make 3 companies the biggest and richest on earth -- while the rest of us are fighting for crumbs. I am running https://picc.io https://picc.io to share images as a link ( think simpler imgur alternative) on some small hosting services. To hell with big tech and to hell with their censorship too!
- dr-smooth 6y agoThe problem I have always had when building elaborate home server setups is the "set it and forget it" nature of the systems I've installed bites me in the ass. Since it's not my full-time job to manage these systems, I'm really not familiar with them the way I might be with the systems I manage at work. These systems cruise along for years, and when something finally does go belly-up, I can't remember how I set it up in the first place. Now I have a giant chore looming over me, ruining a perfectly good weekend. These days, I design everything for home with extreme simplicity coupled with detailed documentation on how I set things up. Docker has helped tremendously, since you can essentially use an out-of-the-box Linux distro with docker installed, and you don't really have to install anything else on the hardware. Then if at all possible, I use standard docker images provided by the software developer with no modifications (maybe some small tweaks in a docker-compose file to map to local resources). Anyway, my advice is to keep the number of customizations to a bare minimum, minimize the number of moving parts in your home solutions, document everything you do (starting with installing the OS all the way through configuring your applications), capture as much of the configuration as you can in declarative formats (like docker compose files), back up all your data, and just as importantly, back up every single configuration file.
- wayoutthere 6y agoThis right here; but even more so. Eventually, whatever platform / tool you use will need to be upgraded. Security vulnerabilities, new features, etc happen and projects like these can get abandoned within a 5-year timeframe. When you have to migrate to either a new or upgraded platform, you have to figure it all out yourself. When the config is broken by an upstream dependency, you’re on the hook too. Who knows if the build tools you used still work on current versions of things. Like it or not, we’re all kind of stuck on these platforms we don’t control. The alternative is to become fluent in yet another technical stack, but one that will be used infrequently and won’t really translate to anything else unless you’re trying to build your own cloud service on consumer-grade hardware.
- mooman219 6y agoLong term platform stability seems to be moving from relying on the OS to higher up in the stack with the advent of Docker. It feels like Docker is being used more and more in cases where I would have considered something like CentOS.
- m___ 6y agoLooks like the author is undecided on what to push next. Hardware - software "solutions" are not the issue, his definition of what his data is worth, to him, as to the pushers as part of an overview of how to stump the global masses is still opaque to the author. F** the data, it is the amassed, filtered, analysed dataset that is globbed over the wire that matters. If the author really has some content with rationality in-built, originality expressed, it is probably half an a4 page in hand-writing. That would be his back-up(so as not to forget what in a bright flash came up in his processor-mind, the once in his life-time), as it would be his legacy to the world. His billing and buying patterns, with his earnings defining his prodigy of consumption not power who cares? What the glob tells about similar individuals, that is what power minds. Above as to repaint the context, really... this article is as close to a reduction to "nothing" as can be conceived.
- whatsmyusername 6y agoOutside Vultr (oof, probably the hosting provider with the second highest amount of malicious traffic coming out of it besides OVH and on our permanent blacklist) solid setup. I'm boring, I just use an external drive kit, hard drives, and an rsync or robocopy script depending on my flavor of the month device. Doesn't spend the money on power to have a NAS going 24/7 and is largely immune to someone oopsieing with ransomware.
- Jyaif 6y ago"Screw it, I’ll host it myself", then proceeds to list half a dozen third party services.
- hn_throwaway_99 6y agoI think it's great that people are publishing their home server setups. At the same time, the scary sounding warnings of "You're at risk if you put your trust in another company to hold your data!!" ring really hollow to me. I mean, does this person keep all of his money under his mattress, or does he put it in a bank (though I guess he could keep it all in crypto...)? Does he buy insurance, or again just keep a mountain of backup cash in a safe somewhere? At the end of the day our entire economy is built around being able to trust other companies, and the systems in place to safeguard that trust. "I'll do it all myself" is essentially the process you see in third world countries where the systems are too fragile or corrupt to support that trust.
- Swenrekcah 6y agoMoney and data are very different in this regard. The systems that keep track of our money are (usually) very secure [0] and when they aren’t there is recourse to fix the damage. A thief can not use the stolen money if the transaction is reversed, but everyone on the planet can abuse your data once it is leaked. [0] At least more secure than the systems those same companies use for their consumer data (see: Equifax).
- bogwog 6y agoMoney in bank accounts is insured by the government, but our data and privacy isn't. > and the systems in place to safeguard that trust How many systems are in place that safeguard our privacy and our data?
- JaggerFoo 6y agoI said "screw it" after my Oracle Cloud "always free" account was terminated with no recourse, a few days after having activity on the database building an application prototype, well under the resource limits. I'm now running a libvirt VM on my laptop to develop the prototype. Others have complained about Oracle Cloud's draconian practices. Doesn't sound like a company that wants to build a cloud business. Cheers
- haolez 6y agoGood to know. I was actually considering giving them a chance in my company due to their competitive pricing.
- phendrenad2 6y agoI think they're making a classic BigCorp mistake: thinking they can just focus on the high-end customers. They don't realize that everything is connected in this industry, and today's hobbyists and sole proprietors are tomorrow's Fortune 500 VPs of Engineering (and vice versa).
- Havoc 6y agoOracle is extra slimey with their "always-free" stuff though. It's free in the sense that you'll have salesmen after you and always as in maybe two months. GCP on the other hand...have been running on their always-free tier for years no. (One of those 1/4 cpu wordpress VMs)
- TheCapeGreek 6y agoIsn't $55 a bit high in total cost? Aside from the 2 servers for projects, all of those aren't going to need entire servers just for 1 user. I've run Nextcloud doing all the same stuff for half that price and don't think Gitea or Monica would add much overhead. I'm aiming to do a lot of the same (and more) but definitely aiming at a much lower monthly cost.
- Havoc 6y agoWould be better off getting 1 large VPS and using nested virtualization (or just straight docker). That way all the services have access to all the cores and you can thin-provision too if desired. (Nested virt being enabled is not a given though)
- djhworld 6y agoI run gitea on a Raspberry Pi and it works ok, along with a couple of other contains + nomad/consul client, it's just me using it and I've had no problems.
- deleted 6y ago[deleted]
- djhworld 6y agoI've been self hosting a few bits and bobs over the years (mainly gitea, FreshRSS reader, pihole, excalidraw and other custom services I've written) Recently I've put together a little Nomad + Consul raspberry pi cluster (3 nodes) to schedule them all in docker containers, with each thing in its own job file. Traefik for routing and HTTPs, which nicely integrates with consul. The cluster setup is all in ansible, which took a while to setup and fine tune but I think (hope?) it's in a good enough place to be able to rebuild the cluster in the event I mess anything up. Clustering might be overkill but I like being able to deploy things through Nomad and it just working without much fuss.
- jonseager 6y agoI’ve been running Nextcloud on a DigitalOcean droplet, backed by S3 compatible storage from Wasabi for about 3 years now - it’s been pretty seamless. I think the old Nextcloud client syncing issues are a thing of the past (unless you work will really big files). Costs me $15/mo total. My Nextcloud instance gets one-way synced using rclone to a NAS once daily, and one-way synced weekly as a tar archive to Onedrive (1TB storage from Office365 is otherwise unused, so...). The rclone setup is all with docker-compose + sops for rclone config, so I can just git clone and Docker-compose anywhere to get another machine backing up. A nice addition is that the droplet serves as a WireGuard server that all my devices are pretty much always connected to (with split routing). I host a couple of other services on the droplet including The Lounge for IRC, my personal website and a pastebin type app. If anyone is interested, the whole setup is on GitHub at https://github.com/jnsgruk/infra https://github.com/jnsgruk/infra
- jonseager 6y agoOh and I should mention, email hosted with Fastmail. Been super happy with it. All the DNS setup etc is Terraform’d in the repo
- everybodyknows 5y agoI chose Fastmail for Yubikey support, and unlimited mail aliases. A little dissatisfied with mail organization tools on the webmail GUI — but it’s also the client for alias creation, so gets frequent use anyway. Are NextCloud email org tools much better?
- jonseager 5y agoCan’t say I have any experience, I tend to use the Fastmail web client, or the standard iOS mail client. Agree with your point on aliases though
- cooervo 6y agoagreed google's customer and creators support is awful. I avoid them as much as possible.
- boramalper 6y agoAs a middle ground, you can also simply use Hetzner's hosted Nextcloud offering, which is likely (a) more reliable and (b) cheaper than a self-hosted setup on a VPS. https://www.hetzner.com/storage/storage-share https://www.hetzner.com/storage/storage-share
- harikb 6y agoWhile I agree shit happens, it is sad to see exaggerated stories without sufficient details being repeatedly quoted by other people https://news.ycombinator.com/item?id=26311417 https://news.ycombinator.com/item?id=26311417 In addition, traditional non-tech companies screw people on a regular basis. I know I am resorting to whataboutism, but let us not panic and try to build our own cloud. One has to consider what happens and when one gets decapitated in a autonomous driving accident and the family is left with a home-made cloud
- bogwog 6y agoThere's nothing exaggerated about that story. Apple cut off access to his accounts and services because of a payment issue (which wasn't even his fault). Even if it was his fault, and he just decided not to make that payment, the story still illustrates how much power Apple has. It's like if you missed a car payment, and the bank used their connections to cut off your cell phone, water, electricity, etc until you paid. Whether or not missing a payment is immoral/wrong, giving a private company so much power over an individual's life is absurd. That's some mafia, break your knee caps with a baseball bat-type shit.
- yosito 6y ago> it’s all fun and games until someone loses access to their private and/or business data because they trusted it to someone else Or it’s all fun and games until someone loses access to their private and/or business data because they lost their encryption keys... there are two sides to that coin.
- ThinkBeat 6y agoWhy so many VPS instances? Does it work out cheaper than increasing the vcpu/ram of one or two units? Is it in case crashes? But then there is no failover I can see.
- worik 6y ago"for purely private use, I wouldn’t opt for AWS even if I had to choose now. I’ll leave it at that" I will elaborate: I started out with AWS several years ago. I could never work out how they calculated my bill, and had more than one >$100 shocks for hosting my personal services. I moved to DO and Vultr (stayed with DO for no real reason) and so shut everything down on AWS. But I still got a $0.50 monthly charge on my credit card. I tried emailing - no response, totally ghosted. I went through the control panel several times - it is/was a huge mess, obscure by policy obviously - and finally in some far distant corner found something still turned on. I did not understand what it was at the time and can recall no details, but I turned it off with great relief. A week later I got a email from AWS (!) saying that I had made a error and they had helpfully turned the whatever it was back on... So I continued to donate $0.50 a month to Amazon until I cancelled the credit card for other reasons. (it would cost $10 for the bank to even think about blocking them) These days I will crawl over cut glass not to do business with that organised bunch of thieves called Amazon.
- divbzero 6y agoThis inspired me to finally track down the $0.XX monthly donation I’ve been making to AWS. Through the billing dashboard [1] I discovered a zombie static site I set up ages ago with S3 and Route 53. [1]: https://console.aws.amazon.com/billing/home#/bills https://console.aws.amazon.com/billing/home#/bills (Edit: I found the S3 bucket, but mysteriously no hosted zone to account for the Route 53 bills ¯\_(ツ)_/¯)
- rnotaro 5y agoI am in the same boat, I'm not personnally using AWS anymore but i'm still charged x.1x$ a month. It's not worth it enough to track the charge down and I might just delete my account without forgetting to change my email adress beforehand (since you can't reuse a deleted account email).
- movedx 5y ago> I went through the control panel several times - it is/was a huge mess, obscure by policy obviously - and finally in some far distant corner found something still turned on. I did not understand what it was at the time and can recall no details, but I turned it off with great relief. Using IAC (Terraform) would solve this in an instant: "terraform destroy". Done.
- wepple 6y agoThe article appears to be complaining that free services don’t have good support, so the solution is to spend $55. Major providers do offer support plans. If google/Apple/Microsoft is so critical to your life and data, perhaps it’s worth paying more than zero dollars for?
- yosito 6y agoWhat did you use to make that data flow diagram?
- doggydogs94 6y agoEvery week or two, I backup my data to an 8T drive. Every year or so, I take the 8T drive off site.
- nichochar 6y agoPeople interested in this topic will likely enjoy the /r/selfhosted subreddit.
- juliend2 6y agoIs there a word or expression for this idea of not relying on big corporations for one's cyber presence, communications and other such tools? I thought about info-independence, but I'm sure someone smarter than I already coined something better by now. I know it is (always?) open source, but not everything open source liberates one from the cloud giants. So there's something there that needs a name, I think.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- manquer 6y agoShoutout to Sovereign[1] nice ansible project to automate most of this kind of home setup [1] https://github.com/sovereign/sovereign https://github.com/sovereign/sovereign
- markozivanovic 6y agoHi, I'm the author, Thank you all so much for your comments. I didn't expect this will be this high on HN. I'm aware there are more simple solutions for self-hosting, even partially. I'm also aware that my setup is not perfect - that's why this post was created. I was hoping to get some feedback. Not from that many of you, but some friends. :) Ask me anything you like, I'll try to answer every question.
- TameAntelope 6y agoThe article sounds like you enjoyed building the system you put together, and I think that's probably a seriously undervalued aspect of why someone might take on this kind of work.
- markozivanovic 6y agoThanks. It is kind of a show-off of what I built for myself. That's why I put that little disclaimer into the post, that it's not for everyone. I do have strong opinions about a lot of the things regarding where I hold my data, but I don't want to strong-arm anyone in doing the same thing.
- ajcp 6y agoI really enjoyed the read, thank you! You're system architecture is very clean and understandable. I spend a lot of time marveling at the beautiful but often overly complex diagrams on r/homelabs, which more often than not dissuade me from actually having a go at it. Your explanation made it feel very approachable. That being said... > Some people think I’m weird because I’m using a personal CRM. This strikes me as incredibly...German, hahaha! Is there any reason your Contacts solution doesn't/can't provide this functionality?
- markozivanovic 6y agoHeh, I'm living and working in Germany, but I'm not German, still (or yet). :) Regarding CRM and Contacts - I could possibly fit all the info in the 'about' field for a particular contact, but Monica offers me so much more. With Monica, I can structure the data for a contact in a better way. That 'better way' and the feature set of Monica is why I'm using it.
- frEdmbx 6y agoCheck out FreedomBox. https://freedombox.org/ https://freedombox.org/
- Daho0n 6y agoHow not to be taken seriously #5781: Preach against Google while using Google crap on the website your are preaching on.
- random5634 6y agoI use AWS - the customer service seems great - I've personally received good service, the support life times are amazing (I used Simple DB). These articles with "I wouldn't use AWS I'll leave it at that.." - be more specific! For personal stuff ECS / fargate works well in my use cases. I put together a little docker and away I go - I pay for one reserved instance which saves money - fargate for stuff that is occasional or bursts (when I started fargate pricing was too high). Docker is in some ways self documenting - I also have a home server setup complete with router etc - but someone is going to bump something at home and the reconfig / resetup time is much longer than with AWS.
- aiisjustanif 6y agoI’m surprised I didn’t see pfsense. Are you using the vpn and firewall built into synology?
- mraza007 6y agoI’ll just mention I have been using vultr for about a year now and I love it. There are no hidden charges and the service is just amazing as I use vulture to host my automated HN newsletter that delivers top news headlines straight to my inbox
- tofaz 6y agoI think one of the main service missing in this project is e-mail. It is very easy to setup your own mail server nowadays...
- FpUser 6y ago20 years ago I've said to myself screw it, quit very well paid but nerve wrecking job in a software development company and never looked back. That's when I also went full remote ( I hire subcontractors but never felt need for an office ) and started hosting my own stuff on rented dedicated servers and in my own office.
- porkbrain 6y agoI've just finished putting together some old machines and setting up my home cluster with k8s, and ported first app on it. Okish way to spend some of my Easter holiday. https://github.com/bausano/cluster/blob/master/changelog.md#2021-04-08 https://github.com/bausano/cluster/blob/master/changelog.md#...
- ineedasername 5y agoI prefer the lower overhead of having things hosted elsewhere, but keep regular backups and have a well detailed business continuity plan for each vendor that could go hostile, belly up, or otherwise no longer viable. You take advantage of off-the-shelf options at the same time that you prepare for the worst.
- nojvek 5y agoThe more I think about owning your data but not having to deal with maintenance crap, I think more tools should work with git. Give me a pretty UI but use my GitHub repo for storage. I kinda want something like notion UI but stores documents as JSON blobs in git (could use GitHub api and GitHub auth too)
- thayne 5y ago> you should consider switching from... Google Maps to OpenStreetMap I've looked into it, but there is very, very little in OpenStreetMap in my area. And I do not have the time, resources, or expertise to map out my entire area enough to make it useful myself. I would like to contribute to the project, but switching over entirely just isn't an option for me.
- habi 5y agoI wonder where you live, do you mind sharing the region? (I have the privilege to live in central Europe, where OSM is actually chock-full of information.)
- thayne 5y agoI live in the rocky mountains area of the USA.
- habi 5y agoI'm genuinely interested, but when I zoom in to a 'random' town in the Rockies I see this - on OSM: https://www.openstreetmap.org/#map=16/40.3730/-105.5230 https://www.openstreetmap.org/#map=16/40.3730/-105.5230 (or https://www.qwant.com/maps/noresult#map=16.00/40.3730000/-105.5230000 https://www.qwant.com/maps/noresult#map=16.00/40.3730000/-10...) - on Google Maps: https://www.google.com/maps/@40.3730,-105.5230,16z https://www.google.com/maps/@40.3730,-105.5230,16z Seems mapped quite good to me. You might find some time to contribute a bit to make OSM even better, all users profit, not only Google :)
- cupcake-unicorn 5y agoWhew, the prices of those VPSes! You can get a VPS for 10 dollars a YEAR! Someone needs to check out lowendtalk.com on black friday...
- jwmoz 5y ago"Is it worth the time and hassle?" No.
- Iv 5y agoIf there is one thing to take away it is this: VPS are cheap, something like 5$/month. Really consider having one, you will quickly use it more than you think. When I was a student I wanted to test things on a distant server so I started renting a cheap OVH instance with SSH to test some silly ideas and host some static pages. It has been 20 years now and it hosts (one of) my backups, a professional website, several docker images, a gitolite and has saved me and colleagues numerous hassles when one of us has to share a few dozen GB of data.
- de6u99er 5y agoLooking through the comments, I think it would be great if someone can bundle all of this into a product which automatically applies security uodates and offers some form of visual dashboard to see the status of the system, errors, and logs of attempts to compromise the system. Furthermore a migration tool from GMail/Google-Apps/Drive would be super useful (+ one for Microsofts offerings). I believe many would be willing to pay for such a service, and I would be open to collaborate on building such a product. I can see here things like: - resale of hardware components and support agreements for paid subscriotions for the software - paid setup support - initial fee of the product - small subscription fee for updates
- js4ever 5y agoI'm working on this, contact me if you want to join your force to the project: joseph at appdrag dot com
- ruph123 5y agoRegarding sever hosting: Hetzner has a very attractive server auction on their website [0]. For about 30€ you can get several terrabytes with a fast cpu and plenty of RAM. No set-up fee either. These are unmanaged dedicated root servers. Basically cancelled sever subscriptions are first offered here again before they take apart the server. So the offerings vary and are time-limited. However, if you pull the trigger there is no limit for how long you can keep using it. Servers are in Germany or Finnland. I am currently waiting for slightly better offerings (a few weeks ago when I found out there were slightly more attractive options) and then will pull the trigger. I yet have to find anything that comes close to this bang-for-buck ratio. [0]: https://www.hetzner.com/sb https://www.hetzner.com/sb
- marceldegraaf 5y agoSeconding this – Hetzner also has pretty decent technical support considering the price. If you get one of their servers, make sure to check the manufacturer and type of hard drives and compare to Backblaze's Hard Drive Stats[1]. Also keep an eye on the S.M.A.R.T. status of your disks. In the past Hetzner has shipped servers with less-than-ideal hard disks (e.g. Seagate ST3000DM001). While their staff is pretty fast in replacing disks they do tend to start breaking all around the same time. [1] https://www.backblaze.com/b2/hard-drive-test-data.html https://www.backblaze.com/b2/hard-drive-test-data.html
- ruph123 5y agoOh thank you, that is good to know. Sadly before ordering a server from the sb, I cannot see the exact HDD models. It just says if it is or isn't the enterprise version and that is it, e.g. like: "2x HDD SATA 2,0 TB Enterprise" Which is too bad.
- marceldegraaf 5y agoThat's right, although in my experience the staff at Hetzner were quick to replace faulty disks in the past. You should be fine if you keep an eye on your disks (e.g. SMART status reports via cron or systemd timers) and contact support before a disk fails entirely.
- Pawka 5y agoJust curious why OP is using Nextcloud apps instead of those which arrives with Synology? Synology also has an alternative for notes, calendar, photos, etc.
- bullen 5y agoI'm also doing a hybrid: GCP (3 nodes; euro, iowa, asia), IONOS as backup in central US, AWS as backup in asia. Then I have two home 1Gb fibers (when my summer house gets fiber this summer hopefully). I wrote my own distributed database so all data is everywhere at all times = no extra work. (after the initial 3 years of making it robust :D) I would say go for the opposite of "use as much standard as possible" and make everything yourself, from scratch (except OS and language); that way you can slowly but surely make it perfect = 100% read uptime even if one home fiber blows up. People that describe this as meaningless don't understand what responsibility is! Own (as in nobody can take something away), understand and change; in that order, on repeat, forever... (until you die and your children pick up the slack because you thought them what responsability is)... People will learn to respect responsability when it's too late.
- acvny 5y agoCompletely misleading title and this is basically an ad: (* Links to Vultr contain my referral code, which means that if you choose to subscribe to Vultr after you clicked on that link, it will earn me a small commission.) host yourself means - running on your own hardware
- tjpnz 5y agoI'm currently working on a MVP for a mobile app with a small Python server side component. In the past I would've spun it up on AWS or GCP but this time I've decided to challenge myself to see how cheaply I can validate my idea. After a few hours of work I got it running on an old Raspberry Pi which I then exposed to the internet with some NAT rules and Duck DNS. Not sure how well this approach would work for something more complex but I'm very happy to have put some old hardware (previously in a box and gathering dust) to work again.
- 8fingerlouie 5y agoAs someone who has selfhosted for a couple of decades, i can understand the lure of it, but the author forgets to mention the huge effort it is to keep public servers available and free of unwanted visitors. I've gone the other way. I had everything on a Synology box at home, backed up locally and remote, with a Proxmox server on a DMZ network, mounting all (data) storage from the Synology via Kerberized NFSv4 through the firewall, and exposing select services to the world (limited by IDS/IPS and geoip filtering) I spent around 1-2 hours daily checking logs, installing patches, checking backups, and other sysadm maintenance jobs. When 2021 rolled around i decided i no longer wanted to be a sysadm in my spare time, so i quit. Everything previously hosted at home was pushed to dedicated hosting providers for that type of service (pythonanywhere for django projects, etc). Not just VPS as that's essentially just self hosting on other peoples hardware. Basic file synchronization went to Microsoft 365 Family. Sensitive data are manually encrypted with either LUKS or Encrypted Sparsebundles. As for my Synology, i pushed all data on it to Jottacloud via rclone and the crypt backend. I then have a machine at home with a 1TB SSD acting as my "NAS", but in reality it's just mounting the Jottacloud data and using the 1TB SSD as a vfs cache. It then exposes the Jottacloud data through Samba. The NAS handles backups of Jottacloud and Onedrive to a local 8TB USB drive. A remote machine wakes up once per day, mounts the cloud shares, and makes a backup as well. In case i get locked out, it's just a matter of restoring one of the backups to whatever storage i have sitting around, and i'm back in business. As for speed, the VFS cache really speeds things up. I get gigabit speeds on cached data, and even uncached data arrives in an acceptable pace (500/500 mbit connection), to the point that when i'm on Wifi (802.11ac Wave2)i can't tell the difference. On top of having a lot less noise around me, i also save about 1/2 the cost of the self hosting hardware spread over a 5 year period.
- ololobus 5y agoThe main thing about building all these private cloud setups, that bothered me most of time is security. It is not a big deal to take from GitHub and run all these bricks of your infrastructure, but how to maintain? Everything should be updated regularly, otherwise you risk to get your data dumped and leaked by some automatic crawler or home-grown hacker, once new vulnerability is discovered in any part of your tech stack. The only easy solution I see is to hide everything in the private network and make accessible only under VPN. However, it is not that useful, when you need to get some file or read/reply email from some new device not owned by you.
- lytefm 5y agoYeah this sounds like way too much maintenance overhead. I've opted in for a middle ground: I don't use FAANG/MS for anything critical and choose other hosted solutions instead. Posteo was already mentioned, Mailbox.org is also nice for E-Mail with an own domain. I only had to set up the DNS records once and rarely have delivery problems. Nextcloud doesn't need to be self-hosted either, there are many good providers.