2 ms·
It sounds like if you rent a VPS/VDS in any other place than Amazon, you'll have to hire a separate person to babysit it 24/7. It's not true.
by anticodon 1y ago
It sounds like if you rent a VPS/VDS in any other place than Amazon, you'll have to hire a separate person to babysit it 24/7. It's not true.
- iLoveOncall 1y agoObviously it's not true, but if you want to put the following on your VPS: > • Ansible roles for PostgreSQL (with automated s3cmd backups + Prometheus metrics) • Hardening tasks (auditd rules, ufw, SSH lockdown, chrony for clock sync) • Rolling web app deploys with rollback + Cloudflare draining • Full monitoring with Prometheus, Alertmanager, Grafana Agent, Loki, and exporters • TLS automation via Certbot in Docker + Ansible You'll spend a heck of a lot of time on setting it up originally, and you will spend a lot of time keeping it up-to-date, maintaining it, and fixing the inevitable issues that will occur. If their bill was 200K a year, why not. But at 24K a year, 25% of an employee's salary, it is negligible and most likely a bad choice.
- sksjvsla 1y agoPeople keep comparing cloud costs to employee costs, but I think that’s the wrong metric. The real ratio to look at is cloud spend vs. the revenue you can unlock. For me, switching from AWS to European providers wasn’t just about saving on cloud bills (though that was a nice bonus). It was about reducing risk and enabling revenue. Relying on U.S. hyperscalers in Europe is becoming too risky — what happens if Safe Harbor doesn’t get renewed? Or if Schrems III (or whatever comes next) finally forces regulators to act? Being able to stay compliant and protect revenue is worth far more than quibbling over which cloud costs a little less.
- anticodon 1y agoSome of these tasks are required when you run your service in Amazon Cloud as well. It's not all free and not all by default. You'll need someone experienced with Amazon Services to set up many of these things in the Amazon cloud as well. Also, it's not like you need everything you mention and need it immediately. NTP clock syncing is a part of any Linux distro for the last 20 years if not more. I don't remember that Amazon automatically locks down SSH (didn't touch AWS for 7-8 years, don't remember such a feature out of the box 8 years ago). Rolling web app deploys with rollback can be implemented in multiple ways, depends on your app, can be quite easy in some instances. Also, it's not something that Amazon can do for you for free, you need to spend some effort on the development side anyways, doesn't matter if you deploy on Amazon or somewhere else. There's no magic bullet that makes automatic rollback free and flawless without development effort.
- sksjvsla 1y agoExactly. Well said. A thing we learned in this process is that there's many levels of abstraction which you can think of rollback and locking down SSH and so on and so forth. If your abstraction level is AWS and the big hyperscalers, it would be to use Kubernetes, but peeling layers of complexity off that, you could also do it with Docker Compose or even Linux programs that are really battle tested for decades. Most ISO certified companies are not at hyperscale so here is a fun one: Instead of Grafana Agent from 2020, you could most likely get away better with rsyslog from 2004. And if you want your EKS cluster to give you insights you have configure CloudWatch yourself so does what hands-off is there comparing that setup to Ubuntu+Grafana Agent?