4 ms·
I remember a comment from this site. Something like: we must study how Amazon and other big cloud's marketing work so great to make this generation developers t
by ies7 3y ago
I remember a comment from this site. Something like: we must study how Amazon and other big cloud's marketing work so great to make this generation developers think that vps or selfhosting are hard.
IMO vps was easy before and even easier now to manage.
- kikimora 3y agoPlease explain how you rotate ssh keys, store audit logs, backup (and test backup procedures), configure secure network between vpses such that your neighbor cannot eavesdrop.
- deleted 3y ago[deleted]
- bcaxis 3y ago* You don't have to rotate what doesn't get out. Limit ingress to relevant IPs reduces this surface area a lot. * SCP to a system built for storage. Not really essential for many systems - system logs are fine. * Every VPS provider comes with a backup check box. * Tailscale is really simple.
- kikimora 3y agoThis is how you protect one small server, you don't need cloud for this. But if you do use it for a small server you'll overpay a lot in relative terms and small amount in absolute terms.
- dpatterbee 3y agoI think on a $5 vps that you're using to host a small website you simply just don't do those things.
- messe 3y agoFor my personal stuff, when it comes to SSH key rotation and secure networks, I like to let Tailscale deal with both. It handles SSH authentication for you via your SSO provider, so there's no need to rotate keys. (Aside: you shouldn't really be using SSH keys to begin with at anything but a small scale. SSH certificates are much more flexible)
- troupo 3y ago1. You didn't do that on a VPS 2. Often there would be a cPanel plugin/extension/app/config value (if the hoster enabled it for you) that would just do for you what you needed.
- tlb 3y agoYou don't need to do any of that for hosting a content website. The content & config are pushed by rsync/ssh from a git repo, so there's no need for backups. I can recreate a server in half an hour. I guess I lose the webserver logs, but I rarely look at them so I don't care. A single server has plenty of bandwidth for a personal site, so there's only one EC2 instance and no secure network is needed. If I need more bandwidth, I'll use a load balancer but there's no need for secure connections between the load balancer & web servers because what's the eavesdropping threat model for a public content site? Let's Encrypt seems to deal with https key rotation without manual intervention. The cloud servers just have the usual ~cloud/.ssh/authorized_keys login setup, and I guess I rotate them every time a stronger crypto is recommended, which is 4ish times in 30 years.
- kikimora 3y agoIf it is just a content website then maybe yes. Cloud complexity probably won’t worth it. Still I can think of a corporate blog, and you have employees come and go then it became a problem even for a small website. Otherwise an angry admin can deface your website and damage your reputation. All other things like secure net won’t apply for a small website, of course.
- fabian2k 3y agoFor a simple use case this is not an issue. - you add your ssh public key to the hosting provider, so any new VM will have it automatically - you use the snapshot service of your hosting provider for backups. If you have a database, run a cronjob that dumps it so it's in the snapshots as well. Alternatively use any backup tool to backup files to somewhere else - you do not need a separate network for simple use cases. Just encrypt traffic if you have multiple servers, odds are you only have one here anyway.
- arandomusername 3y agoCloud is just merchant of complexity