4 ms·
> How does being docker compose based make it inaccessible? Because it requires people to also have knowledge about the ins and outs of docker and docker compo
by creesch 27d ago
> How does being docker compose based make it inaccessible?
Because it requires people to also have knowledge about the ins and outs of docker and docker compose. If we are talking about web applications it is yet another layer that has been added over the years. It used to be that you could fairly easily host most things on a old fashioned lamp host (I am talking decades ago) and all you had to know was basic file transferring.
Of course, this was on shared webhosts in a time when VPSes were not really a thing yet or affordable. But, even on a VPS setting up a LAMP stack is relatively straightforward.
Once you add modern dockerized application to that mix you are now still looking at some sort of ingress to do the reverse proxy bit. So while it likely will not be Apache or nginx there will be some sort of layer there in addition to now having to setup docker properly (rootless and all that) and then also making sure your docker compose setup is in order.
It is not difficult *once you know how to* but it is another layer of knowledge and experience people need to acquire. That does make it less accessible for novices.
- kursus 27d ago> you could fairly easily host most things on a old fashioned lamp host (I am talking decades ago) and all you had to know was basic file transferring Setting up and maintaining a server is easier today than it was decades ago, A LAMP at this time meant a lot of manual setup, IaC wasn't a thing, reproducibility wasn't a goal, versioning was confidential, documentation was scarce and often outdated, out of the box security was lower, ties to the OS were higher. Managing virtual hosts was clunky, updating OS/PHP was risky. I would not go back for anything. > having to setup docker properly (rootless and all that) Rootless being the proper way to setup Docker is a highly controversial take. You will mostly get added complexity and a false sentiment of security from it.
- creesch 27d ago> Setting up and maintaining a server is easier today than it was decades ago, A LAMP at this time meant a lot of manual setup, IaC wasn't a thing, reproducibility wasn't a goal, versioning was confidential, documentation was scarce and often outdated, out of the box security was lower, ties to the OS were higher. Managing virtual hosts was clunky, updating OS/PHP was risky. I would not go back for anything. You are speeding past my point by a mile or two. With a shared webhost you get a ready lamp stack. In the late 90s early 2000s you could fairly easily get a wide array of software running that way. All you had to do is create a database in the hosters control panel, upload the package and you'd be on your way. Later in the 2000s one click installers came along for popular packages making it even easier. In fact, they are still around these days making it extremely easy to install a wide array of lamp based applications to these days. There are very few options these days to get started as easily these days with modern non lamp tech stacks. The only thing I am familiar with (other than the product presented to us in this post) is pikapods, [which only offers a limited selection of available applications](https://www.pikapods.com/apps https://www.pikapods.com/apps). There are a few others, also catalog based, though they more seem to focus on deploying on other platforms for you. Other than that you start to quickly move to more complex hosting solutions aimed at business and scaling. Or platforms that are cloud platforms with all the added complexity to navigate and figure out before you can deploy docker containers. Not to mention ridiculous situation that a few of the ones I know about have pivoted to being "agentic compute providers" whatever that means and certainly will confuse a novice. Which means that the "practical" advice given is often to "just" set up a VPS. And yes, many VPS providers will provide an image with docker enabled, but that is just the start. > Rootless being the proper way to setup Docker is a highly controversial take. You will mostly get added complexity and a false sentiment of security from it. That, in fact, is another layer of complexity people will then have to figure out. Most information I am aware of these days does claim that it is better to run containers rootless or at the very least make sure the user in the container is non root. The fact that we are both convinced of the opposite tells you how confusing it must be for a novice. The overall point I am trying to make isn't even about the exact details. It is that for hosting something these days there is much more required surrounding knowledge required before you can get started in most cases.
- xorcist 27d ago> A LAMP at this time meant a lot of manual setup, IaC wasn't a thing, I'm sorry but this is just nonsense. LAMP is called that because it was a very standardized thing. Pop in a Debian CD and select a ready made profile for it. There were even ready made installers for Windows and Mac if you weren't on an Internet native operating system. A lot more people got by using custom bash scripts, but cfengine exited in the 90s. It's still not honest to say things were more manual. Take a look at /r/homelab or somewhere selfhosters hang out today and look at the Compose or self hosted K8s stacks people set up today. That's orders of magnitude more manual work than just popping in a CD and selecting LAMP. Yes, those are not the same thing. Yes, a self hosted stack today consists of so much more than running PHP in a web server. But for self hosters, the amount of work required has objectively gone through the roof. That's a problem if your goal is data sovereignty.
- kursus 27d ago> op in a Debian CD and select a ready made profile for it. At the time in question here tasksel wasn't a thing, I think merely a concept. It made its way in Debian installer around 20005 IIRC, right along "one-click installs" from hosting services mentioned in the other reply. The whole decade before that, indeed manual set up was needed. > at /r/homelab or somewhere selfhosters hang out today [...] That's orders of magnitude more manual work There is two kinds of self-hosters, those who aim at reproducibility and those who don't. The latter is more fun, the former gets quickly mandatory when you _rely_ on your homelab.
- spockz 27d agoDo you have any sources on why rootless is just false security posturing?
- venusenvy47 27d agoI don't like using Docker on a VPS because of the way it bypasses the firewall rules. It's such a pain that I avoid it altogether for anything public.
- spockz 27d agoDocker doesn’t do that on my Fedora machine, nor on my arch machine. Did I set some setting somewhere that I forgot about? I’m also running rootless docker and podman so that might explain.
- lesostep 26d agoJust to clarify: if you "sudo ufw deny 80" and than run a docker container on 80 port, your 80 port would remain inaccessible (as per ufw rules)? Even rootless docker usually pierce through that. Might be some setting in a podman, thought, never really worked with that.