3 ms·
"The reason many start with cloud is that most businesses quickly grow, or at least hope to quickly grow, to the point where they'll need it" And most don't. T
by codegeek 2y ago
"The reason many start with cloud is that most businesses quickly grow, or at least hope to quickly grow, to the point where they'll need it"
And most don't. That's the point of the article.
- mjr00 2y agoMost don't, but you can get a t3.micro RDS database and EC2 instance for less than $20/month, to service those two requests per second you're getting. I would assume most startup founders in the US can afford this. If they can but consider it too unlikely they'll recoup these costs, you're getting into "hobby project" territory rather than business.
- erik_seaberg 2y agoThis. A single dedicated bare metal server sacrifices too much availability, in return for capacity that you probably don't need yet. Better to use a fraction of a few different servers.
- gadflyinyoureye 2y agoThis is true if you don’t follow best practices. That RDS instance should be in a private VPV. You should have a NAT bridge to your public VPC. That bridge is $35 a month. Then you need a public thing: be it EC2 or API Gateway or ALB with rules. That can more your total to $50/month. But it’s more secure than a Digital Ocean or Hetzner setup.
- mjr00 2y agoWell yes, if you start adding "best practices" that only apply to larger companies with threat models that are completely nonapplicable to your 0-revenue, 2-request/sec startup, you are going to have to pay more money. Adding the requirement of separate private/public VPCs linked by a NAT gateway when we're comparing to a single physical machine with everything running in a single host running Docker is nonsense.
- snoman 2y agoI think you’ve confused a couple of things. Your db should be in a private subnet as opposed to a VPC, and it’s never advised to have public access directly to your db. You also don’t need NAT for RDS instances as they shouldn’t be initiating outbound connections to the internet. If you do want to connect to your db from outside of AWS for ad hoc connections then you should be setting up a bastion host in the public subnet and you don’t need anything other than security group rules to configure communication between them - same goes for a web server (routing between public/private subnets are configured out of the box).