21 ms·
The architecture behind a one-person tech startup
- de6u99er 5y agoThis looks solid. And k8s makes total sense, since you are avoiding vendor lock-in. I'm just wondering why you don't also run your managed services in k8s?
- iamflimflam1 5y agoIt makes sense to leave managed services outside. Do you really want to be responsible for maintaining your Postgres database? Dealing with upgrades, backups, replication etc... Much better to leave that to the cloud provider to manage. From the article: > However, as a project grows, like Panelbear, I move the database out of the cluster into RDS, and let AWS take care of encrypted backups, security updates and all the other stuff that’s no fun to mess up.
- ThePhysicist 5y agoIt's a great writeup, I just find it weird that the author runs his "privacy-focused" analytics service on AWS and Cloudflare. From a GDPR perspective it's not even clear if this is lawful (Schrems-II), and there are some good alternative cloud services available in the EU (e.g. Hetzner or OVH). Also, Cloudflare still sets the __cf* cookie on every request, so it's not really cookieless tracking (I'm aware that Cloudflare is planning to get rid off this cookie though). Edit: Maybe the downvoters can explain what they're disagreeing with?
- de6u99er 5y agoOn AWS you can chose the geographic location where you run your stuff. I guess the author is running them in EU zones. Regardinging CloudFlare cookies, I am not sure if this is the authors problem, since I guess he is neither processing nor storing any data about it.
- ThePhysicist 5y agoSure, I still find it's a weird choice for a privacy-focused service. Also it's not clear that the Cloudflare cookie is really required to ensure the functionality of a web service (it probably isnt' as they're planning to get rid off it), so just pretending that you don't need to inform customers about this cookie set by your data processor is mere wishful thinking. Again, no one cares much about this and it's not enforced, if you're building a privacy-focused service you should give it some thought though instead of just saying "Cloudflare is cool because it gives me free TLS and load balancing". Just my 2c.
- villasv 5y ago> From a GDPR perspective it's not even clear if this is even lawful It is pretty clear it is
- ThePhysicist 5y agoNo it's not, you can check e.g. the EDPB's recommendation [1] on this. At the very least you'd need to use data mapping and ensure EU citizens data stays within the EU, the author's service advertises "200 edge locations around the world" so I'm skeptical whether data won't leave the EU. Not many companies care about this and there's little enforcement so far, I think it's fair to think about this though if you're running a privacy-focused web service from Germany. [1] https://edpb.europa.eu/sites/edpb/files/consultation/edpb_recommendations_202001_supplementarymeasurestransferstools_en.pdf https://edpb.europa.eu/sites/edpb/files/consultation/edpb_re...
- villasv 5y agoIt's pretty clear that using AWS is lawful. What you're questioning is if AWS is being used in a compliant manner, which is an entirely different thing. It is possible to do so, so there's nothing odd with choosing AWS.
- ThePhysicist 5y agoPersonally I find it odd to choose AWS (and Cloudflare) for running a privacy-focused service out of Germany. But again, that's just my personal opinion, I guess most people here are fine with this setup. And I'm also at least a bit doubtful that a one-person startup can get all compliance aspects of running services in a global AWS and Cloudflare-based setup right, so I'd recommend using infrastructure that by default will be hosted in the EU so you don't have to worry about this.
- moooo99 5y agoYou don't have to obey the GDPR for users outside the EU, so as long as the central storage is located in the EU (and only replicated across EU countries, which is easily configurable), the author is most likely absolutely fine. By the edge locations, I'd assume he's serving cached static files, such as his blog or tracking scripts from there using CloudFlare. Assuming CloudFlare is not falsely advertising their GDPR compliance, the author is also fine.
- chrisandchris 5y ago> From a technical point of view, this SaaS processes a large amount of requests per second from anywhere in the world, and stores the data in an efficient format for real time querying. That is the closes thing to a number of requests I could find. So this architecture, no matter how solid, is somewhere between „way to large“ and „matches perfect“. It seems like a solid breakdown on how to deploy your services to k8s and how to properly do CD deployments. But it does never mention whether it actually makes sense at the scale he actually has.
- k__ 5y agoYes, K8s seems a bit overkill for such a service. But if you like to work with K8s and it motivates you to stay on task, why not?
- danjac 5y ago> I use Kubernetes on AWS, but don’t fall into the trap of thinking you need this. I learned these tools over several years mentored by a very patient team. I'm productive because this is what I know best, and I can focus on shipping stuff instead. Your mileage may vary. This is a key point. I don't know Kubernetes, and for this kind of scale I'd probably use, say, Heroku. But if I did know Kubernetes, I'd probably use it as it would be one less thing I'd have to worry about if I had to scale up quickly: you never know if that little side project with a dozen users is going to become an overnight success.
- attilakun 5y agoThis is the kind of problem that is good to have. I think in the majority of cases, the real problem is getting customers in the door.
- adamhp 5y ago> But it does never mention whether it actually makes sense at the scale he actually has. What does "make sense" in this context mean? It sounds like you're assuming he chose K8s for the scalability, but scalability isn't the only consideration here. Familiarity of the tooling is the biggest one that he mentions in the post. He even goes so far as to say that k8s probably isn't right for everyone, it's just what he knows. It's efficiently supporting a profitable application and requires minimal maintenance. That seems to accomplish the goals of "infrastructure", broadly speaking.
- eandre 5y agoSuper interesting! Definitely feels like a lot of fairly low-level tech to have to deal with for a one-person company, but I guess that doesn't surprise me any more :)
- marcosdumay 5y agoIdeally, your ops complexity increases with the volume of traffic it handles, not with the number of people managing it.
- eandre 5y agoIn the ideal case it should be constant and as close to zero as possible! Of course we don't live in that world for arbitrary scale, but surely "a one person SaaS" should be able to do without so much low-level tech and infrastructure work. It seems to me that even when you outsource your infrastructure to a major cloud provider, you're still spending a lot of time yourself setting everything up. I'm certainly not criticising Anthony here – what he's done, especially in terms of product development, is remarkable – but just thinking about the industry at large.
- wmichelin 5y agoHow do you start learning this breadth of software engineering? I consider myself good in the python / django space, but where do I start with learning these infrastructure technologies? I find that I use them once or twice periodically, and then don't touch them for so long, so I forget much of what I have learned.
- bombcar 5y agoDocument everything in excruciating detail - I go so far as to record all the commands I run; and when complete o destroy the machine and start again (or use a separate system) and verify that I accurately recorded every step. You can add additional text about why you did certain things - and then store the data in a wiki or checked into git or similar so you can find it when you need it.
- shoey 5y agoWhat is your system for keeping all of these notes. Do you just have a git repo for everything?
- darekkay 5y agoNot OP, but I've been keeping a "journal" repo for the last 4 months. There's a single dev.md file in there, where I separate each entry with "---". Whenever I encounter an issue or learn something new, I document it for later reference.
- RotaryTelephone 5y agoI do same and keep everything in Evernote organized in subfolders and tagged. Quick to find and helps 100% when it's time to rebuild/setup a server.
- bombcar 5y agoIt honestly depends on what it is - sometimes in the repository, for a wiki it’s stored in the wiki itself, otherwise it might be as simple as a text file in a web directory.
- throwaway823882 5y agoCool write-up. I am a K8s hater, but I can see how this can work well for small projects with 1 developer. EKS definitely takes a lot of the maintenance headache, but there'll still be some down the line.
- rufusroflpunch 5y agoI always feel like these write-ups about SaaS's are written by people who make SaaS's for other SaaS's. Application monitoring, email marketing, etc.
- totalminimalist 5y agoI've done a few of these for people at home (albeit not quite so complex) and for myself. I built the application/infrastructure monitoring systems where I work as well. As one poster said above, document everything, even the commands. It works, although it is tedious. But there is a certain joy using something you created, even if it is something of a "labor of love" to maintain it. I want to get out of IT after 20 years, but there is no way I will stop tinkering with OSs, Raspberry Pi IoT devices, SoC, light coding, etc. It's different when it's a hobby than when you're faced with time constraints, budgets, and nagging bosses. A project I'm about to start at home is taking an existing 1080P dash cam (front and rear) that features great night vision and hack it using a Raspberry Pi that handles motion detection, sends stills, and uploads to the cloud. Sure, I could go buy an extant system that just works, but what's the fun in that? It's like Legos. I could go buy my kid a fully-assembled car or spaceship, but I'd rather him learn how to follow instructions, see cause and effect, and experience the pride of a job well done. YMMV. There is something really uplifting in seeing "complex" technical stuff working that you yourself built. It doesn't even have to be as good as existing tech.
- unculture 5y agoIt's probably a function of to whom a one man band can effectively market. Consumers don't buy SaaS and a single person couldn't afford a consumer level brand ad campaign anyway. Big companies mean big company sales cycles and demands - procurement departments, compliance etc. Other SaaS companies are easier to find in places like HN, and they're maybe more predisposed towards buying from lone hackers like this one.
- AznHisoka 5y agoHow are those examples intended for just SaaS? Application monitoring and email marketing are used in all industries.
- 5y ago
- siruva07 5y agoHas there ever been a one-wo(man) SaaS founder to take a company public?
- smrk007 5y agoDo you mean taking a company public without any co-founders and employees, or starting originally with none, then later taking some on? If the latter, I would think Dropbox would count, since at least originally it was a single founder.
- siruva07 5y agoI mean IPO’d with one employee - the founder
- pcthrowaway 5y agoI suspect IPO would be impossible with one 'person'. You'd have other people on payroll: Lawyers and accountants at the very least. If you're paying millions of dollars to professionals anyway at a certain point it would more sense to hire the people directly, right?
- siruva07 5y agoMaybe not. Conceivably, everyone could be on payroll as contractors except the founder.
- say_it_as_it_is 5y agoI was under the impression that Kubernetes was a complicated beast not meant for small teams / startups. What is the value of it in this monolith environment? Is the key to using it in a startup context to use it as a basic monolith auto-scaling orchestrator but no more than that? If you or anyone else here can comment about how to use Kubernetes strategically without falling into an unnecessary over-engineering rabbit hole, I'm willing to learn from you. Regarding the rate limiting, you're load balancing into nginx services that you've configured to limit requests. Are they synchronizing rate limiting state? I can't seem to find nginx documentation supporting this. What value is there in this style of rate limiting, considering User X can send a sequence of requests into a load balancer that routes them to nginx boxes A, B, and C? The big picture that 3 requests were processed for user X gets lost. Your endpoint-level rate limiting, however, may potentially be achieving the synchronized rates if the redis servers in a cluster are synchronizing. I guess I'm asking about the strategy of using multiple lines of rate limiting defense. Is nginx-level rate limiting primarily for denial of service? The horizontal autoscaler should be based on throughput rather than hardware consumption, shouldn't it? If the req/sec goes below a threshold, spawn a new service. Can anyone comment?
- anarsdk 5y agoDrive-by addressing the HorizontalPodAutoscaler (HPA) question you have. It depends. If you want to scale on other metrics than cpu/mem, then HPA can do custom metrics too. See https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/#support-for-custom-metrics https://kubernetes.io/docs/tasks/run-application/horizontal-... Specifically the Prometheus Adapter.
- HugoDaniel 5y agoThen reality hits, and most SaaS's typically only need to handle about ~10 reqs/day, those of the "founder".
- potatoman22 5y agoYour words, why do they sting so true :(
- medicineman 5y agoBecause marketing costs money, not just time.
- rory 5y agoMy one-man-SaaS setup: - Static frontend hosted on Netlify (free unlimited scale) - Backend server on Google App Engine (connecting to Gcloud storage and managed DB via magic) I realize I'm opening myself up to vendor lock-in and increased costs down the road (if I even get that far), but I've wrangled enough Docker/k8s/Ingress setups in the past to know it's just not worth the time and effort for a non-master.
- mark_l_watson 5y agoInteresting, thanks. I used to use Google AppEngine a lot and very much liked it, but haven’t touched it for years. Now, I like the idea of using Heroku better, and just pay a little more.
- devoutsalsa 5y agoHeroku my feels cheaper when you think about how long you can punt on having ops proper person(s) & how much time you save rolling your own everything.
- nocommandline 5y agoIf you don't mind my asking, can you say why you moved from GAE to Heroku and/or why you prefer Heroku over GAE?
- mark_l_watson 5y agoI used them both in the same time period. I liked GAE because it was basically free to use for low use web apps, but has scalability built in. I liked Heroku because it was just so easy to develop and deploy with.
- toomanybeersies 5y agoMy experience of Heroku has mostly been the pain of migrating to a different platform once you grow to the point that their pricing (and abstraction) starts to act against your growth. Heroku is great for general applications, but if you're trying to do something that isn't a standard CRUD app, it can really start to bite you in the arse. Their DB pricing in particular is incredibly inflexible compared to AWS RDS. Among other issues we had with Heroku at my old job, was having a DB that was hitting its storage limits, but was miles away from hitting its memory or connection limits. There was no option but to upgrade to the next tier, with additional memory etc., even though all we needed was additional disk. That's not to say that Heroku is bad, but like any tool, you need to be aware of the long term costs that are often associated with term convenience.
- anonymouse008 5y agoAnthony - if you're reading this, thank you!! To arrive at this architecture takes 100s if not 100s of hours, and to share it with the community is dang inspiring. I was feeling a bit down on my projects, but this has me amped up seeing how the ultimate goal of working on features rather than deployment is possible, and very real! Best of luck with Panelbear!
- amzans 5y agoThank you! I appreciate it. Glad you found it helpful.
- FBISurveillance 5y agoFantastic, well written, detailed post, please share more of these.
- wakatime 5y agoI really enjoyed your post too! I would be interested in more details around the "100s of hours". I want to try a k8s setup like yours, but after investing those 100s of hours into my Flask setup it's hard to justify spending that time again for something else when this already works. Also interested in the costs for your setup. My costs are in my other comment [1]. [1] https://news.ycombinator.com/item?id=26740911 https://news.ycombinator.com/item?id=26740911
- suifbwish 5y agoYou should be able to run a flask app pretty easily in kube. Basically you would build a docker image containing the app then deploy it with k8 I believe
- wmichelin 5y agoThis is a dramatic oversimplification of how complex it is for a python developer to configure and deploy an application on kubernetes.
- 0xdba 5y agoFor my typing SaaS, I found firebase hosting/realtime DB a ginormous time saver. And since it hasn't taken off (and probably won't ever), it just costs me a pennies a month since I'm under their free limits, plus the domain.
- darkhorse13 5y agoBut you should be careful if it actually does takeoff. Firebase is freaking amazing, but the pricing can get crazy expensive.
- elitan 5y agoI also tested Firebase but quickly ran into issues. Firebase's database is a NoSQL database, whereas almost all my data for the apps and (micro-)SaaS I was building had relational data. Their frontend data fetching felt clunky and did not fit my requirement. Also, the fact that Firebase is a closed-source backend felt scary in the hands of Google (https://killedbygoogle.com/ https://killedbygoogle.com/). Firebase's problems and my desire to have the perfect backend made me build an open-source alternative to fix all the shortcomings. PostgreSQL instead of NoSQL. GraphQL instead of REST. 100% open source. That is now https://nhost.io https://nhost.io.
- darkhorse13 5y agoThanks for sharing. On first impressions, I found Nhost's product to be really cool, so much so that I actually applied for the open position of Product Designer [Tahmid].
- 0xdba 5y agoThat is a problem I'd love to have.
- throwaway78123 5y agoThis goes against the HN trope that "you don't need Kubernetes unless you are Google-size". It turns out Kubernetes is actually perfect for small teams as it solves many hard operational issues, allowing you to focus on the important part of the stack: the application. The key is to stick to a simple setup (try not to mess with networking config) and use a managed offering such as GKE. We may need a Kubernetes, The Good Parts guide.
- heipei 5y agoKubernetes, The Good Parts: See Hashicorp Nomad ;)
- jdoss 5y ago100% this. Hashicorp Nomad is a breath of fresh air in comparison to Kubernetes.
- rattray 5y agoFor the lazy: From https://www.nomadproject.io/docs/nomad-vs-kubernetes https://www.nomadproject.io/docs/nomad-vs-kubernetes > Kubernetes aims to provide all the features needed to run Docker-based applications including cluster management, scheduling, service discovery, monitoring, secrets management and more. Nomad only aims to focus on cluster management and scheduling and is designed with the Unix philosophy of having a small scope while composing with tools like [Hashicorp] Consul for service discovery/service mesh and [Hashicorp] Vault for secret management. > Nomad is architecturally much simpler. Nomad is a single binary, both for clients and servers, and requires no external services for coordination or storage. Nomad combines a lightweight resource manager and a sophisticated scheduler into a single system. By default, Nomad is distributed, highly available, and operationally simple.
- throwaway823882 5y agoLike all of Hashicorp's tools, they are more complicated and error-prone than they first appear, because they stuff too much functionality in one binary. But it does let you implement one piece at a time, so you can make incremental improvements as you need them.
- dimeatree 5y agoGood on them. I wish I could use K8 as effectively as the author, it is an incredibly overwhelming list and an impressive range of knowledge. In my situation I am finding the lack of consistent environment a reoccuring issue, the developer environment does not match production. However I kept it simple with Google App Engine Standard and Flex environments, I found the deployment process simple and was enough for me (at the time) - however I am finding we are going to step into dockerland; however I feel like it is very over my head!
- elbear 5y agoHave you considered Nix and NixOS? It also has a high learning curve, but it provides better reproducibility.
- omarhaneef 5y agoI hate to give homework to other people but I suggest you expand this out: udemy class, booklet, or a series of blog posts with tasteful ads. Ideally, you would get it to the point where a newbie can use it as a reference.
- michaelbuckbee 5y agoAn important distinction here is that PanelBear (OP's One Man SAAS) is something I would define as an "analytics" SAAS and as such has requirements that are way above what a typical CRUD SaaS might have. That's not to take anything away from the excellent writeup, but more so that someone who is thinking about starting a SaaS maybe doesn't jump to the conclusion of "I should go learn Kubernetes".
- mritchie712 5y agoYep, and their recommendation on Render is a good one. I used it for a SaaS / fintech app I built and it couldn't be easier to work with. Great support too if you need it.
- deleted 5y ago[deleted]
- ccmcarey 5y agoGreat writeup. How do you handle database migrations when using an otherwise automated CI/CD flow with gradual deployment?
- rkwz 5y agoYou can use any normal DB migration tool. For k8s, I put the app's readiness probe to false, run the migrations and then toggle the probe back to true. Here are some migration libraries: Go - https://github.com/golang-migrate/migrate https://github.com/golang-migrate/migrate Node - https://github.com/salsita/node-pg-migrate https://github.com/salsita/node-pg-migrate
- slt2021 5y agoI wonder what happens during blue green or canary deployment? if your migration changes database schema in a way that affect previous version negatively? is it even possible to do blue/green deploy if your schema changes radically?
- rkwz 5y agoIt's definitely possible but we need to spend sometime to make sure the changes are backwards compatible and gradually rollout the destructive change. Here's a really good guide on how to do this - https://docs.gitlab.com/ee/development/avoiding_downtime_in_migrations.html https://docs.gitlab.com/ee/development/avoiding_downtime_in_...
- slt2021 5y agothank you very much! this is a treasure find for me
- Mavvie 5y agoIt's fine if you make the changes backwards compatible a version. And in general, any change can be done in a backwards compatible way (although it can be a PITA)
- 5y ago
- knodi 5y agoI have done with before, ran and one man b2b saas platform with 30clients from around the world. Infrastructure was the easiest part. We where processing roughly 100million messages a day, about 5 nodes. Monitoring was good, application performance tracking was good. Business ran for close to 7 years, making about 1.3mill a year on an average year.
- bulte-rs 5y agoCare to elaborate on the use of past tense? I.e.: are you no longer in business, sold it or no longer running it solo?
- knodi 5y agoYes, I no longer have the business. It got harder and harder to compete with larger players as the market begin to attract more players. I sold of the business to a larger company (just contracts and not tech).
- hu3 5y agoWhat was the hard part?
- knodi 5y agoHard part was support. Due to my clients being from around the world, sometimes they need help with items and expect a certain level of service, such and responses to support questions with in 24 hours or sometimes sooner. This required me to 90% of the time forward the inquiry to the a upstream vendor and that took time to collateral the right data to vendor (from the client's inquiry). I did end up hiring a support personal for help to give me some breathing room on the weekends.
- lmarcos 5y agoNice read. I haven't seen any references to Ansible or similar tools. For the ones who know: given the architecture described in the article, does Ansible fit in the picture? I don't know a lot of k8s but I wonder how VMs are provisioned (e.g., how docker is installed?)
- pokgak 5y agoThey mentioned using managed Kubernetes. Normally that means the VM provisioning is managed by the cloud provider.
- kparaju 5y agoIn the authors case, terraform will create the EKS (kubernetes) cluster, which then is responsible for creating the EC2 instances. The actual application containers are then created by EKS.
- Sodman 5y agoA lot of people are going to jump on the "he used k8s and he doesn't even work at Google scale!" part of this writeup, but I think it's a perfect demonstration of the concept of innovation tokens [1]. He admits in TFA that clickhouse was the only new piece of tech in his stack, and he was already familiar with k8s et al - so he's able to focus on actually building the products he wants. I could see somebody unfamiliar with k8s (but very familiar with all other pieces of tech in the system they want to build) being able to learn it as part of a side project, if it's the only new thing. Where the wheels come off is when you've never touched k8s, postgres, aws, rust, graphQL or vue - and you try to mash them all together in one ambitious project. [1] https://mcfunley.com/choose-boring-technology https://mcfunley.com/choose-boring-technology
- cloverich 5y agoInnovation tokens is such a fantastic concept. When I brainstorm products I like to make a simple plan, and then map out "Whats new to me" to help me decide what I am really trying to accomplish. Prototyping a new idea is very hard and requires a lot of iteration, using a new tech complicates that even if its better. Alternatively, if the prototype is purely for fun, then new tech can be a great value add, as even if the prototype takes a turn for the worse (i.e. too hard to finish), you get satisfaction from learning some new tech. I've noticed since being very intentional about it, side project work has become considerably more enjoyable.
- void_mint 5y ago> Where the wheels come off is when you've never touched k8s, postgres, aws, rust, graphQL or vue - and you try to mash them all together in one ambitious project. In my experience (both myself and observing others) this is the cause of lots of side project (sometimes even startup) failure. Lots of people choose a tech stack that's far away from what they've worked with, so they never get past the "read the docs and try to get anything working" stage. For a real chance at completion it seems like the recipe for success is choosing a stack that's 1ish derivative away from a dev's competencies so they have a new and exciting thing to learn, but are able to continue progressing and adding value. I am also a person that, prior to using Azure, was an absolute "Kubernetes is a big waste of my time and I'll just skip it" person. I wrote it off as predominantly "resume-driven". Now, having used Azure for about a year, I'm rewriting all my Azure infra to use AKS to better insulate me from the inevitable issues that come up when I GTFO of the Azure sphere as soon as our credits run dry. And, what I'm learning, is Kubernetes is a just-fine deployment/orchestration/management tool for containerized infrastructure that is _not_ a massively complex microservices infra. It's just a more streamlined approach to scaling and managing cloud-agnostic tooling/containers.
- eruci 5y agoMy one man SaaS setup: t4g.micro (Free Trial) on AWS Ec2 - one mod_perl module + a bunch of python/perl scripts. ( https://poidata.xyz https://poidata.xyz ). Startup costs so far=$1 (domain registration).
- ilovefood 5y agoI use Nomad for this after 2 years Kubernetes and it has been a revelation that things shouldn't be complicated. Won't change back again.
- sa1 5y agoThe author almost seems to apologize for having a django monolith. But it's worth realising that one purpose of code organisation in larger companies is to mirror the team organisation. That's a constraint on code that can interfere with the best technical architecture. You can do better with a monolith in a one-man team!
- efficax 5y agoyou can do better with a monolith on a ten-person team, or a 300 person team. Monoliths have their advantages
- KineticLensman 5y ago> one purpose of code organisation in larger companies is to mirror the team organisation. Sometimes, the organisational structure drives the code structure (Conway's law [0]). I've seen real world consequences of this, where the disconnected system stovepipes in a large organisation reflected the team structure of the organisation's purchasing function. The purchasing teams didn't speak to each other, so neither did the systems they purchased. The systems had separate support contracts, incompatible upgrades, and each one was a wholly distinct integration target, if you were a third party. [0] https://en.wikipedia.org/wiki/Conway%27s_law https://en.wikipedia.org/wiki/Conway%27s_law
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- oreally 5y ago> one purpose of code organisation in larger companies is to mirror the team organisation. That's one of the weirdest reasonings I've ever heard. What happens when you have to downsize that team? But yea, shoehorn each individual contributor to say a single microservice out of a hundred and you'll wonder why your software doesn't develop fast - everyone's too tired trying to understand what each abstraction does that is meaningful so they spend less time understanding how the pipeline works and how to integrate into it.
- urashidmalik 5y agoAmazing!. How long did it take to reach this point from envisioning the idea.
- btbuildem 5y agoLeading with a little blurb about WHAT the solution does would be nice.
- mrwnmonm 5y agoAnyone knows the chart lib he is using in the frontend?
- staticelf 5y agoInteresting post. I would advice people against running a kubernetes / docker setup if you don't know it well. It's quite complicated and most small companies don't really need it. As the author say, he already got a lot of experience of it so it worked out great for him but it is probably easier just to install the tech needed for a small company. Unless you have something very special going on, the dependencies (like databases) are probably not going to be that many.
- sillycube 5y agoI use docker compose on a DO droplet, 1 container for python / django, 1 for postgresql, 1 for nginx. Kubernetes is too complicated for me
- igammarays 5y agoAnyone heard of a One Man SaaS unicorn, i.e. a product that scaled to $10m+ ARR with only a single founder right till the end?
- macNchz 5y agoI believe Plenty of Fish (a dating site) was in that category for some time, though the founder did wind up hiring people before eventually selling it for $575m.
- hardwaresofton 5y agoI'd argue that just about every infrastructure that looks like this benefits from Kubernetes (that you're not setting up and managing), and that's a lot of them. The biggest problem is that not enough people have boiled down Kubernetes enough to look like heroku yet. Google Cloud Run is possibly the best example of what Kubernetes can look like/run like -- it runs on (probably a relatively heavily modified) KNative, a project that runs on top of kubernetes. The "point" of Kubernetes is to drop the difficulty of building a service like Cloud Run to zero. It drops the cost of building a Heroku down to zero. I'd bet my bottom dollar that fly.io and render are running on Kubernetes (maybe they mentioned it somewhere already and I just missed it). With the right cluster set up, building one of those platforms (or others that I won't mention) is almost as simple as setting up stripe checkout and writing a web interface to turn form fields into JSON fields and send them to a kubernetes cluster (possibly with hard multi-tenancy! not to get too into it, but you can literally provision kubernetes clusters from kubernetes clusters, ephemeral or otherwise). No other tool in the devops world except for maybe the initial orchestrator wave (ansible/puppet/salt/chef) has been this much of a force multiplier. Ok, maybe that's hyperbole, but if adhoc-bash-scripts->ansible is 1->2, Ansible->Kubernetes is similarly 1->2, especially if you consider baked in cloud provider support/innovation. But here's the secret -- perversely, I'm happy deep down that everyone thinks k8s is too complicated/is a buzzword/isn't worth the effort. All it means to me is that I'm still ahead of the curve.
- corford 5y agoFly.io is running on Nomad last I heard.
- hardwaresofton 5y agoYou’re right, I stand corrected: > The problem is mitigated somewhat by our orchestration system. The control plane for Fly.io is Hashicorp Nomad, about which we will be writing more in the future. https://fly.io/blog/persistent-storage-and-fast-remote-builds/ https://fly.io/blog/persistent-storage-and-fast-remote-build...
- leoedin 5y ago
- undeadsushi 5y agoI'm currently using zappa and lambda for supporting about 25 b2b users. It's a django / react application and I use cloudwatch for scheduled cron jobs. My overall cost is <$20 a month.
- ernsheong 5y agoI am also a one-man SaaS (though not a successful one). The following tends to be my stack (on Google Cloud, if you will): - Cloud Run (serverless containers) - Cloud SQL (via proxy) - Cloud Monitoring & Logging (formerly Stackdriver) - Compute Engine (if necessary, e.g. websockets) - Cloud Build for GitOps (deploy on push) It's clean and simple (to me). Billing is in one place, nicely separated by projects. Monitoring & Logging is already built in. No need to span multiple dev SaaS tools. So far managed to avoid Redis caching because Golang + Postgres is fast enough, so far. But if you need Redis you can DIY on Compute Engine or try Cloud Memorystore (configure the memory to a low amount for cost savings). Google Cloud drawbacks: Additional charges necessary to connect Cloud Run to VPC (via proxy instances). Load balancing on GCP ain't cheap ($18/month, though to a larger enterprise that is a rounding error). But in my setup I didn't need these things. As shown above, I have heavily optimized for cost and simplicity in my setup.
- spyspy 5y agoCloud Run supports websockets now fyi. This is the approach, more or less, that I use for my personal projects. With CR and Firestore are literally free for my use cases. I only pay a few cents to host some static assets in GCS.
- ernsheong 5y agoWebsockets on Cloud Run is $$$, from what I saw, so be careful. Basically it keeps the instance on.
- zomgwat 5y agoAre you happy with Cloud Monitoring? I ended up moving away from it. I find the UI to be too slow for the purpose it serves. I'm fine with a slow-ish app sometimes but not when I have to use it often and during incidents. I also had a few instances over the course of several years where policies seemed to have transparently broke because a system metric name changed. It's possible the issues were of my doing but I don't think they were. Lastly Monitoring, Tracing and Error Reporting are too disjointed. I wanted a solution that created a more holistic view of what's going on.
- pier25 5y agoSince you're in Germany, how do you handle VAT, EU tax returns, invoices, etc? What about taxes and invoices to other countries?
- nodamage 5y agoI am wondering about this too. Tax compliance is complicated and Stripe doesn't do much for you on this front.
- amzans 5y agoIn short, it’s painful :) Looking into a Stripe plugin like https://www.quaderno.io/ https://www.quaderno.io/ I really enjoy using Stripe, and their support is great, but sales tax compliance makes me a bit jealous of those using Paddle.
- 1hakr 5y agoThanks for sharing, very detailed. i might use some ideas for my own SaaS https://simpleops.io/ https://simpleops.io/
- aaronbrethorst 5y agoMy one-person SaaS architecture: It’s a Rails monolith deployed on Heroku. I’d rather have the time to build new features for my user base than spend it learning how to use k8s or wrangling AWS through its abysmal console website.
- barnabees 5y agoDo you think you're better than the OP because you're using a simpler stack?
- mediaman 5y agoI don't think he's arguing that. Just that a simple stack that's boring can work well for a SaaS whose success is not contingent on huge traffic. For many successful SaaS companies, if their model is not monetizing huge traffic through ads, traffic is really not a metric of success. And they can be financially successful handling only paltry traffic. Lots of business-problem-solving apps fall into this space. Sure, maybe you only have 60 customers using your app. But if each one is paying you $1,000 a month...
- ysavir 5y agoIt's about solving every problem in due time. Starting with an easily scalable infrastructure, if the need for a scalable infrastructure is either unproven or distant, is not the best use current resources. It's more cost-effective and beneficial to use an out-of-the-box tool like Heroku and spend our time building the product that people will actually be paying for. There might come a time where the hosting costs on Heroku are getting frighteningly high, but even then it's something that might not be high priority. If the profit impact of building and maintain a K8 infrastructure is less than the profit impact of building a new feature and securing more users, then by all means, let's continue paying Heroku and focus on what makes the business more sustainable. The time to convert from a simple setup like Heroku to a scalable system like K8 is when that change has the biggest net impact on the company's operation.
- aaronbrethorst 5y agoNope, just different. I'm a big proponent of the notion of 'innovation tokens,' which has come up elsewhere in this discussion[1]. If the project that I was referring to had been a 'just for me, just for learning' side project, I would have chosen one new-to-me technology. It might have been some JavaScript SPA framework. It might have been Kubernetes. Or maybe GraphQL. It might have been something completely different. But, this project was absolutely critical for its users, and it had to be delivered on an incredibly tight timeline. I didn't have the luxury of playing around with anything new. And this is still the case. In fact, the project has grown in importance for its users and I have even less flexibility to play around with new-to-me technologies right now. --- [1] Here's an example of me discussing this six years ago, although I was unfamiliar with the term at the time: https://news.ycombinator.com/item?id=9291437 https://news.ycombinator.com/item?id=9291437 ... Re-reading this comment, I'm actually kind of surprised how little I disagree with here. The only thing that has actually changed for me is that I use Swift instead of Objective-C for my iOS apps.
- ijustwanttovote 5y agoI really enjoy reading these to learn the infra behind one man bands. Another good read is Wenbin from Listen notes. https://www.listennotes.com/blog/how-i-accidentally-built-a-podcast-api-business-46/ https://www.listennotes.com/blog/how-i-accidentally-built-a-...
- wenbin 5y agoAnthony, this is awesome!
- yalogin 5y agoThis is probably not the best place to ask this question, but as a solo founder or just to reduce costs/time are there some standard free software packages that are used when creating sites? For example most sites need a user sign up mechaism, a authN and authX mechanism to gate access to different pages. Are there open source projects that provide this? Or do site owners develop these from scratch every time?
- ryanSrich 5y agoDepending on your software stack, there are several open source projects that can provide functionality out of the box. If you don't mind paying just a little bit of money, you can get even more out of the box SaaS like functionality with tools like Jumpstart (if you're using Rails). https://jumpstartrails.com/ https://jumpstartrails.com/
- deleted 5y ago[deleted]
- glutamate 5y agoDepends on the framework you use. Rails and Django have a lot of this built in or as widely used plug-ins. In node.js you have to do a lot from scratch every time, or you can use a service that provides this like Auth0
- mattferderer 5y agoYou might find this useful - https://github.com/gothinkster/realworld https://github.com/gothinkster/realworld Different framework implementations of a CRUD website with authentication. A lot of popular web frameworks have basic authentication out of the box & easily allow you to tie free authentication with accounts like Google, Microsoft, and many others. There are also paid alternatives that may save you more money than the free ones if you need advanced authorization controls or other features. Most devs probably have a collection of ways they've done it in the past that they pull from when needing to adjust from the default framework's methods.
- ggregoire 5y ago
- kparaju 5y agoThanks for a great post! It was super detailed and I loved reading it. I had a quick question about your pg setup. You mentioned that you use EBS for your persistence storage, which is locked by zone . You can't have an EC2 instance in Zone 1 mount a storage in Zone 3. Does this cause issues with your db? Especially as you have HPA and ClusterAutoscaler, your k8s nodes could be spun up in Zone 1 for pg autoscaling but your data is in Zone 3.
- efortis 5y agoMy infrastructure is $2,800/year. There are two Servers load balanced with DNS. Each Server has 3 jails (Nginx, App, DB) and 2 NICs The internal NIC is for replicating the DB, and for the App Servers to target the Primary one. Diagram and Configs: https://blog.uidrafter.com/engineering/freebsd-jails-network-setup https://blog.uidrafter.com/engineering/freebsd-jails-network...
- arminiusreturns 5y agoHey great job on the documentation! So nice to see it done well.
- efortis 5y agoThank you!
- xianwen 5y agoVery interesting. Do you mind sharing the hardware specifications of your servers? Are you confident that FreeBSD is a secure OS to face the internet, say, as compared to OpenBSD?
- efortis 5y agoHi xianwen, Both servers are SuperMicro with: - 6 Cores 3.3/4.5GHz (E-2136) - 32GB ECC DDR4 - 2 × NICs (em, igb) - 2 × 480GB SSD - 20TB on 1Gbps with DDoS FENS - IPMI over VPN I rent them to Hivelocity. === FreeBSD vs OpenBSD Ilja van Sprundel answers your question by comparing the number of kernel vulnerabilities since 1999 of the BSDs and Linux. [1] I don't think FreeBSD, even well hardened [2], is as secure as OpenBSD. After all, OpenBSD's main focus is security. I use OpenBSD for orchestration and monitoring, and I have an experimental setup of OpenBSD with VMM but they crash sporadically, so I'll wait a bit. At any rate, my goal is to have two heteregenous paths (maybe OpenBSD, FreeBSD) or (Solaris, Linux). This way I could simply shutoff the vulnerable path when there's an unfixed vulnerability. [1] https://youtu.be/rRg2vuwF1hY?t=264 https://youtu.be/rRg2vuwF1hY?t=264 [2] https://vez.mrsk.me/freebsd-defaults.html https://vez.mrsk.me/freebsd-defaults.html === BTW, I have the FreeBSD hardening and setup scripted, which you could add into the ISO in `/etc/installerconfig`, or downloaded from the orchestration and manually ran with `bsdintall script myinstallerconfig.sh` if you wish.
- anurag 5y ago(Render founder) This is incredible work, and underscores the reason Render exists and is recommended by OP. Everything mentioned in the post is baked into Render already: * Automatic DNS, SSL, and Load Balancing * Automated rollouts and rollbacks * Health checks and zero downtime deploys (let it crash) * Horizontal autoscaling (in early access!) * Application data caching (one-click ClickHouse and Redis) * Built-in cron jobs * Zero-config secrets and environment variable management * Managed PostgreSQL * DNS-based service discovery with private networking * Infrastructure-as-Code * Native logging and monitoring and 3rd-party integrations (LogDNA, Datadog, more coming this month!) * Slack notifications More at https://render.com https://render.com.
- wakatime 5y agoMy one-person SaaS architecture with over 250k users: * Flask + Flask-Login + Flask-SQLAlchemy [1] * uWSGI app servers [2] * Nginx web servers [3] * Dramatiq/Celery with RabbitMQ for background tasks * Combination of Postgres, S3, and DigitalOcean Spaces for storing customer data [4] * SSDB (disk-based Redis) for caching, global locks, rate limiting, queues and counters used in application logic, etc [5] I like how OP shows the service providers he uses, and why he decides not to self-host those parts of his infra. Also, there's a large up front cost involved for any stack (Rails, Django, k8s). I'd be interested in a more detailed writeup with configs, to try out OP's auto-scaling setup. My configs are linked in the gist below [2] for my non-auto-scaling Flask setup. I spend about $4,000/mo on infra costs. S3 is $400/mo, Mailgun $600/mo, and DigitalOcean is $3,000/mo. Our scale/server load might be different, but I'm still interested in what the costs would be with your setup. [1] https://wakatime.com/blog/33-flask-part-2-building-a-restful-api https://wakatime.com/blog/33-flask-part-2-building-a-restful... [2] https://gist.github.com/alanhamlett/ac34e683efec731990a75ab69d5699a1 https://gist.github.com/alanhamlett/ac34e683efec731990a75ab6... [3] https://wakatime.com/blog/23-how-to-scale-ssl-with-haproxy-and-nginx https://wakatime.com/blog/23-how-to-scale-ssl-with-haproxy-a... [4] https://wakatime.com/blog/46-latency-of-digitalocean-spaces-vs-aws-s3 https://wakatime.com/blog/46-latency-of-digitalocean-spaces-... [5] https://wakatime.com/blog/45-using-a-diskbased-redis-clone-to-reduce-aws-s3-bill https://wakatime.com/blog/45-using-a-diskbased-redis-clone-t...
- tluyben2 5y agoI am running a few one man saas's on a 2.99$ vps (1 per project) with php, mysql and nginx.
- jmt_ 5y agoWhere are you renting a VPS for 2.99$/mo? OVH?
- marvinblum 5y agoProbably Hetzner.
- munawwar 5y agoHetzner, Scaleway..
- medicineman 5y agoJust curious, but how scalable would this be? Is it a non-issue in your market segments?
- system2 5y agoDepends on how much you make from a client per month. If your product is $19 - 99 or whatever you can stick, $2.99 or $5 really doesn't mean much just to keep things simple. We do the same for the projects we have. Droplets with custom ISO (created from the original project) takes about 5 minutes to deploy and serve with new credentials to the new users. These infrastructures are I see in these posts really don't align with most single fullstack devs out there.
- yumraj 5y agoDoes anyone know how those diagrams are drawn?
- brianbolger 5y agoLooks a lot like mingrammer https://diagrams.mingrammer.com/ https://diagrams.mingrammer.com/
- biztos 5y agoGood article. My comment might be off topic in which case, please ignore. If you have a one-person SaaS company, how do you get past customers’ resistance to a single point of failure, namely you? Do you pretend you’re not just one person? Do you only have customers who could handle losing the service when you, say, run away to meditate on the mountaintop? (Or get run over by a beer truck, or whatever.) Is there some non-obvious solution? And — back on topic — is the architecture part of that sales pitch? “I’m just one dude, but look how simple this is, it can run itself if I am devoured by mice!”
- dangrossman 5y agoI've made a living running one-person SaaS sites for over 20 years, many of them in the same space as OP (analytics stuff). I can't recall a customer ever asking how many employees there are. It just doesn't come up. I don't think small business customers care. Maybe it matters for more enterprise salesy type businesses.
- GordonS 5y agoI'm in a very similar situation - I've ran a one-person, B2B SaaS for 20 years, and not once has anyone asked how many employees we are. I sell a lot in the EU defence sector, and even there is has never come up. Sometimes customers ask about product end-of-life policies, but they are always satisfied with my responses.
- groundthrower 5y agoI run a b2b saas that is used daily by some fortune500s. I have been going through rigorous vetting processes but have only once been asked about this. I lied and told them it is no problem. I usually pretend my company is larger than it is (me). It gives me a headache now and then, and am now in the process to get someone else onboard.
- paul_f 5y agoThis is a great question. It never ever comes up during the sales process, I don't go out of the way to show them my (lack of) org chart. If you do customization for larger customers (and you should), like boiling a frog, one day you become mission critical to their business. Once they recognize that, then they will start asking questions. Now they're kinda stuck with you. You did charge enough money, right? At that point you must appease them with a plan. Have their code and database on a dedicated server instance. Have them pay for it and own the account (you just saved money). Make sure you're using their domain they control. Give them access to the source code. It's on the server, so that's easy. Write up a doc with how to access everything and all the frameworks and tools you use. After this, they will never bring it up again. Worst case scenario, sell them the software outright. Price it much higher than you think they will pay. Then double that. Trust me, I've done this a few times.
- rajatsx 5y agoMy one-man-SaaS setup: - A single VPS server to host the app. I love DigitalOcean. - A single docker-compose file to bring up the entire stack containing the front-end, the back-end and the database. - Caddy for automatic SSL certificates and proxying. - JavaScript/TypeScript for building stuff. - Cloudflare For DNS
- eweise 5y agoThis looks way too complicated.
- riantogo 5y agoOne person forum platform setup: -Inmotion shared hosting (some $10/mo fixed) -PHP (codeigniter framework) with MySQL Not very proud in the age of Cloud, but I can’t deal with all the complexities. Command line scares me (which seems to be the requirement these days for any development). Now I have a simple ftp folder mapped directly in VS Code.
- dikaio 5y agoWow what a great post, thanks for sharing!
- albertTJames 5y agoThe secret management seems overly complex, why not use https://aws.amazon.com/blogs/containers/aws-secrets-controller-poc/ https://aws.amazon.com/blogs/containers/aws-secrets-controll... or https://kubernetes.io/docs/concepts/configuration/secret/ https://kubernetes.io/docs/concepts/configuration/secret/ ?
- dimitrios1 5y agoOne thing I noticed a lot with indie or "one-man" startups is they make ample use of other SaaS tooling, often lesser heard of or known ones as well. I am not sure what the right answer is, but I at least appreciate that there founders out there willing to give the little-er shops a chance. A healthy ecosystem with competition is good for the most amount of people.
- chpmrc 5y agoHey great post! Thanks for sharing so many details. Just one question: how do you approach profiling in production? Specifically in those cases where copying whatever slice of data from the prod DB would be too much to handle.
- dpweb 5y agoAs a one person company I find it not just helpful but a core principle to minimize the number of stacks/tools/services being used. Overhead of task switching and learning curves.
- singhrac 5y agoReminds me of Listen Notes: https://www.listennotes.com/blog/the-boring-technology-behind-a-one-person-23/ https://www.listennotes.com/blog/the-boring-technology-behin...
- reubens 5y agoI love your landing page. Accessible, well-balanced... you clearly have garnered a degree of frontend experience to complement the work on the backend
- nodamage 5y agoIf you're using Stripe for billing how do you handle tax compliance, specifically related to the VAT requirements in each EU country as well as sales tax requirements in each US state?
- lemarchr 5y agoIt's probably fine, but reading about a single Postgres container in a Kubernetes cluster with backups to S3 gives me sweaty palms. I hope the author has fully tested their disaster recovery plan.
- nickthemagicman 5y agoWho was the very successful startup guy who ran all of his services from a single digital ocean VPS?
- c17r 5y agoI think you're thinking of https://levels.io/ https://levels.io/
- cadbox1 5y agoI don't have the startup part yet but here's my one-person stack with Postgres, Node and React deployed on AWS with CDK using RDS, Lambda, S3 and Cloudfront. It's 100% in the free tier. https://github.com/cadbox1/prawn-stack https://github.com/cadbox1/prawn-stack
- tptacek 5y agoThis is really well done. A suggestion, hopefully helpful: a better approach to securing your admin console than simply layering 2FA onto it would be to expose it to a private WireGuard network. One very easy way to do that is with Tailscale, which will hook up to your GSuite authentication --- Google's 2FA stack will be far better than anything you'd likely build on your own. Tailscale is disgustingly simple to set up. If you're a product person, it's actually upsetting how easy they've made it to get set up.
- maxioatic 5y agoI setup Tailscale for my home server the other day, can vouch for how disgusting it is. I thought it would take at least an hour, but no, took about 5 minutes. Was, literally, physically taken aback (in a good way). Highly recommend it.
- mjgs 5y agoImpressive Tony Stark level solo dev setup :)
- deleted 5y ago[deleted]
- msmagh 5y agoLoved reading this, thanks for putting in the effort to share with community.
- johndoe42377 5y agoWow, this is worse than node_modules. So all this crap is required to run a Django app? Wrappers over wrappers over wrappers. IT is broken beyond repair. And fucking J2EE now looks normal.
- peter_d_sherman 5y agoPanelbear's homepage: https://panelbear.com/ https://panelbear.com/ >"Web Performance and Traffic Insights From the small stuff to the big picture, Panelbear gives you the insights you need while respecting the privacy of your visitors. It's simple, and fast." Price is based on client websites' page views per month, with free tier to 5K page views.
- umen 5y agoDoes some one here build multiplayer game mobile or web setup and can share ?
- mikestaub 5y agoI created a similar post a while back for the GRANTS stack. ( GraphQL, React, ArangoDB, Nodejs, Typescript, Serverless ) https://github.com/mikestaub/slack-lunch-club https://github.com/mikestaub/slack-lunch-club
- alexellisuk 5y agoI was just reading the beginning of Arvid Kahl's Zero to Sold. He recommends using a tech stack that you already know and have lots of muscle memory with. I couldn't agree with him more. [1] This tech stack looks over-engineered upon first glance, but I don't know much about the author or his product. I use Kubernetes a fair bit whilst developing OpenFaaS and teaching people about K3s, but there is a whole world of development teams who aren't prepared to consider it as an option. One of the reasons we created "faasd" [2] (single-node OpenFaaS) was to help people who just wanted to run some code, but didn't want to take "Kubernetes mastery 101" For a small app using a managed service like Cloud Run plus some cloud storage should get you very far. I saw that Heroku is still popular with the indie community, with the author of Bannerbear getting a lot of value from the managed platform. [1] https://thebootstrappedfounder.com/ https://thebootstrappedfounder.com/ [2] https://github.com/openfaas/faasd https://github.com/openfaas/faasd
- system2 5y agoDigital Ocean / Vultr + Ubuntu droplets solve everything for us. We slap a sucuri in front of it, or for cheaper projects Cloudflare. I can't understand the complexity people come up with like this.
- nicioan 5y agoGreat write up! Reminded me of the "The boring technology behind a one-person Internet company" [0] and the HN discussion [1]. [0] https://www.listennotes.com/blog/the-boring-technology-behind-a-one-person-23/ https://www.listennotes.com/blog/the-boring-technology-behin... [1] https://news.ycombinator.com/item?id=20985875 https://news.ycombinator.com/item?id=20985875
- bellttyler 5y agoIn the beginning my startup only had 2 people. A designer (my friend) and me (a developer). For our frontend we used Webflow. My friend was able to create the entire marketting site, and all the app UI's without needing help from me. Webflow is an awesome tool for that sort of thing. For the backend, I built a simple Node/Express API and hosted via Heroku. To this day, everything is still running fine and the API is processing roughly 200 million requests a month. The total cost to host that on heroku is $50/mo. You can definitely have a simple stack but have it be highly scaleable!
- plnii 5y agoI run a one-person SaaS company supporting three products. One is an iOS and Android all-local storage app so that costs me nothing to run. I have two projects running on Django sharing the same RDS DB. I can support two apps with just a single EC2 each. One runs docker containers. The other I did not dockerize yet. For me, the total costs are about $40/month. I have looked at Netlify and other “easy options” but they double or more my costs due to their costly basic tiers.