4 ms·
It means you take responsibility of maintaining the server forever, i.e. dealing with TLS certificates, SSH keys, security updates, OS/package updates, monitori
by kennu 6mo ago
It means you take responsibility of maintaining the server forever, i.e. dealing with TLS certificates, SSH keys, security updates, OS/package updates, monitoring, reboots when stuck, redeploy when VPS retired, etc. Usually things work fine for a year or two and then stuff starts to get old and need attention and eat your time.
- shimman 6mo agoThis is extremely easy with tools like dokploy tho... I use dokploy locally to manage all my VPSs + home server. Truly good stuff and I don't believe your quip at the end, it feels like poisoning the open source waters for consolidated anti democratic cloud platforms. It's way way way way easier managing a basic VPS that can be highly performant for your needs. If this was 2010, I'd agree with you but tooling and practices have gotten so much better over the last decade (especially the last 5 years).
- kennu 6mo agoMaybe you're right - I've never tried dokploy, but from documentation it sounds like mostly a deployment, monitoring and alerting tool. For me the problem has always been that once you get the alert (or something just stops working), a human needs to react to it and make things work again. In cloud services you mostly pay for them providing the human, and in self-hosting you're the human. I can see though that today's AI models could eventually replace the human in the loop and truly automatically fix every possible situation.
- c-hendricks 6mo agoI must be using the wrong cloud services. Whenever a part of our app goes down someone on the team still needs to respond to it.
- bdangubic 6mo agoyou actually need new ops teammates, not new cloud services :)
- kennu 6mo agoYou might be right. I've been mostly using serverless / managed cloud services such as AWS Lambda, API Gateway, S3, DynamoDB for the past 10+ years. When I've needed to respond, it's been because I myself deployed a bad update and needed to roll it back, or a third party integration broke. The cloud platform itself has been very stable, and during the couple of bigger incidents that have happened, I've just waited for AWS to fix it and for things to start working again.
- wouldbecouldbe 6mo agoyeah i've had more downtime on managed db's & cloud servers then on my own managed VPS. And if it happens, with VPS i can normally fix it instantly compared to waiting 20-60 min for a response, just to let you know they start fixing it. And when they fix it, it doesnt always mean your instance automatically works.
- satvikpendem 6mo agoAgreed, Dokploy is great, not sure why you got downvoted for the suggestion.
- shimman 6mo agoIDK, I only found out about Dokploy six months ago. The tools nowadays for managing small hosted solutions is absolutely amazing. You can do a lot with a single VPS if you avoid bloated software choices. People often forget there is a massive economy out there for niche solutions and if you're a small team you don't exactly need a large slice to make a nice life for yourself.
- SoftTalker 6mo agovs. trusting someone else to do all that for you, and do you then verify that it gets done properly?
- kennu 6mo agoWhen buying the infrastructure as a managed cloud service, yes, I trust that they've got people handling it better than I could myself. The value proposition is that I don't even see the underlying infrastructure below a certain level, and they take care of it.
- fnoef 6mo agoOh no! Issuing SSL certificates! The horror! I really doubt that people who can’t install an ssh key should be able to practice software engineering. Sometimes, I think that software engineering should be a protected profession like other types of engineering. At least it will filter out the people who can’t keep their OS up to date.
- asadm 6mo agoTime is a precious (and really expensive for SWEs) resource, why should one spend it on updating certs and instances?
- satvikpendem 6mo agoThey shouldn't, that's why self hosted PaaS already do it for you, it's not a differential reason to use cloud services instead just because they do it for you too.
- sgarland 6mo agoYou don’t, you automate it. This has been a solved problem for literally years.
- simpsond 6mo agoNow you have to maintain the automation. There is nothing wrong with that. There is nothing wrong with building your own server. There is nothing wrong with colocation. There is nothing wrong with driving to the colo to investigate an outage. There is nothing wrong with licensing arm and having TSMC fab your chip. There is nothing wrong with choosing which level of abstraction you prefer!
- kennu 6mo agoThis is not about how easy or difficult it is to issue TLS certificates, to configure SSH keys or to update the OS. It's about having to actively maintain them yourself in every possible situation until eternity, like when TLS versions are deprecated, SSH key algorithms are quantum-hacked, backward-incompatible new OS LTS versions are released, and so on. You will always have new stuff come up that you need to take care of.
- ipsento606 6mo agocertbot and ssh keys are things you set up once I haven't rebooted my DO droplets in something like 5 years. I don't monitor anything. None of them have been "retired".
- wouldbecouldbe 6mo agojust ask claude to do all that :), he is excellent and installing & managing new servers and making sure all security patches are updated. Just be careful if its a high risk project.
- gbuk2013 6mo agoAs someone who runs a such a VPS this is all a non-issue. Running HTTP service is so trivial that once I set it up I don’t even spend an hour in a year maintaining it. Especially with Caddy which takes care of all the certs for you. And this is also bearing in mind that I complicate my setup a bit by running the different sites in docker containers with Caddy acting as a proxy. With storage volumes for data and a few Bash scripts the whole server becomes throw-away that can be rebuilt in minutes if I really need to go there. And for sure any difficulty and ops overhead pales in comparison to having to manage tooling and dependencies for a typical simple JS web-app. :)
- mvdtnz 6mo agoThis is the kind of stuff a software develop should have absolutely no problem managing. It's crazy to me that so many software developers hate the idea of maintaing a computer.
- xandrius 6mo agoYou clearly haven't tried doing that in quite a long while. Using SSH keys + fail2ban means that for a simple static site, it will be sufficient for a decade at least. TLS certificates get auto-renewed with letsencrypt every 3 months via certbot. Installing security updates depends heavily on what is your threat model, if you're just displaying some static content you fully own, you'll be usually fine. Literally never seen a VPS being "retired", if it happened to you, change provider. I've got a bunch of VPS running for 10+ years, I never need to touch them anymore. My homelab has been going strong for the past 8 years. I did have to do some upgrade/maintenance work to go from being an old laptop without screen to a minitower low power machine, and when I added 30TB of storage. Other than that, it's running smoothly, it also uses TLS and all the rest.