6 ms·
Love self-hosting and really got into it over the last couple of months. I run a bunch of services for my company now and also in my home lab. I use a Hetzner V
by asar 2y ago
Love self-hosting and really got into it over the last couple of months. I run a bunch of services for my company now and also in my home lab. I use a Hetzner VPS and provision things either via ansible + docker compose files or via https://github.com/coollabsio/coolify/ https://github.com/coollabsio/coolify/.
The awesome-selfhosted repository is also a great place to find projects to self-host but lacks some features for ease-of-use, which is why I've created a directory with some UX improvements on https://selfhostedworld.com https://selfhostedworld.com. It has search, filters projects by stars, trending, date and also has a dark-mode.
- b_shulha 2y agoAny chance to get my SaaS into "Heroku alternatives" section as well? https://ptah.sh https://ptah.sh
- user_7832 2y agoSince you seem knowledgeable on this topic I'd like to ask - how risky is it to expose a computer on your network to the internet, if you're somewhat tech-savvy but not very familiar with networking? Is it relatively "safe" with modern tools and VMs or do you need to stay on top and (for eg) always ensure you're updating software weekly? I've thought of setting up and running a server for a long time and finally have a spare laptop so I'm thinking of actually running a NAS at least.
- voidUpdate 2y agoYou'll want to make sure everything stays up to date in case someone finds a vulnerability in whatever software you're currently using. If you have to expose stuff to the outside world, only open the ports you need to. Only allow access to a specific user with a non-default username (or at the very least disable root ssh access), and use long passwords or ssh keys. I think that's generally the bare minimum, but there are online guides to harden your stuff further like using wireguard and fail2ban and stuff
- asar 2y agoThe approach most people use is to tunnel into the server. You install a daemon on your computer which establishes a tunnel to log-into from outside your network. Cloudflare and Tailscale have solutions for this that are very popular among the self-hosted crowd. https://developers.cloudflare.com/cloudflare-one/applications/configure-apps/self-hosted-apps/ https://developers.cloudflare.com/cloudflare-one/application... https://tailscale.com/kb/1151/what-is-tailscale https://tailscale.com/kb/1151/what-is-tailscale
- conradklnspl 2y agoA god option is to setup a wireguard connection between workstation and servers. All traffic has to go through wireguard. Because wireguard is UDP and only responds to valid requests, there isn't any open port from the outside. Not even ssh.
- jimvdv 2y agoAdditionally you can use Tailscale for added convenience. Tailscale is a payed service, for a simple home server you can get away with the free plan and their mobile apps work rather well. Not affiliated with Tailscale at all just shouting them out because they do make things very easy and I often recommend them to hobbyist.
- packetlost 2y agoI've been doing it for about 13 years now with HTTP/s (80, 443), SSH (22), MOSH (lol idk), and IRC (6697) exposed to the internet. You don't need it, but something like fail2ban or crowdsec is a good idea. You will get spammed with attempts to break in using default passwords for commodity routers (Ubiquiti's `ubnt` is rather popular), but if you're up to date and take a few minor precautions it's not all that hard and/or dangerous. That being said, there are alternatives such as Tailscale that are strictly more secure but far less flexible. I've heard of people using Cloudflare tunnels as well, but I'd rather not rely on big players for stuff like that if I'm going through the effort to self host (and don't have any real risk of DDoS). I would try to set up automatic updates for critical security patches or update about weekly. I know people that self host and do it monthly and they seem fine too. Most anything super scary vulnerability wise is on the front page here for awhile, so if you read regularly you'll probably see when a quick update is prudent. I personally use NixOS for all of my servers and have auto-updates configured to run daily. An old laptop is exactly how I got started 13 years ago, they're great because they tend to be pretty power efficient and quiet too.
- bongobingo1 2y agoHm, is there a name for the type of software that Coolify is, where it presents a management plane for other servers, vs Dokku where it runs on the server?
- b_shulha 2y agoCoolify and others mentioned on that website can run on the server itself as well. It happened that Coolify provides the paid option to sponsor the development, but it is not mandatory.
- apitman 2y agoThis is pretty nice. I see sish and inlets. I have a lot more similar tools on my list here: https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling For auth, I also made a comparison of OIDC servers here: https://github.com/lastlogin-net/obligator#comparison-is-the-thief-of-joy https://github.com/lastlogin-net/obligator#comparison-is-the...