This is one of the reasons why web security is as bad as it is.
Even so heroku is not the right choice for this, way too expensive.
For me, Heroku has always been the choice over AWS or Digital Ocean. I haven't had it block me from doing anything I've wanted to do and my monthly bill is around $10 (for multiple sites). For my projects, I could never make a solid argument that moving away from Heroku would actually change the product for the end user in any meaningful way. And with the greater amount of time and energy I would need to focus on a non-Heroku server-side, it would likely slow progress.
I'm just too lazy to switch it over, honestly. I don't think it's a difference between "building it myself" and "using someone else's solution." It's about an hour of setup, maybe 2 if I encounter headaches. I probably ought to do it, given it'll earn me $35-40 per month forever.
It's clear that the author was overspending—even a small dyno with a resource-hungry language like Rails can do a lot of traffic—but there's a lot more than just installing a web server, DB. Firewalls? WAL-E backups? Monitoring (of any kind)? A correct TLS setup? DB security?
Setting those up—in a way that you can replicate if the box is hosed—is a whole 'nother side project unto itself. Learning Ansible, Salt, etc. is great, but if your goal is to build X thing as a side-project, you'll never get anything done in a timely manner if you start reinventing wheels.
Plus, they recommend against[1] enabling backups for I/O heavy VMs (so, databases) because of the copy-on-write implementation and its effect on I/O performance.
I ended up going to AWS because I was tired of having to string together a web of iptables rules (e.g. when you provision a new webserver VM you have to iterate over your Postgres, Redis, HAProxy, Elasticsearch, etc. VMs to poke holes in their firewalls), setup WAL-E and monitoring it / testing backups, setup 3rd party monitoring VM resources for issues (CPU/memory/disk space), having to manage package updates and security fixes, aggregating logs to a 3rd party with rsyslog, all that stuff.
Unless your app is a complete throwaway that you don't care about getting hacked or losing all your data, you quickly have to start worrying about this stuff and it becomes a huge burden to roll it yourself on VPS providers.
[1]: https://www.digitalocean.com/community/tutorials/understandi...
I've attempted a number of times to bootstrap up my apps on DO, AWS, docker stuff, etc - all in anger. The Heroku tax is less than the time spent configuring, maintaining and monitoring my own servers.
In economic terms, this is called opportunity cost. That's time I could spent building features or playing guitar.
It's that they didn't exercise the sort of thrift possible with a website that has no users, and I'd wager that they didn't really know how to since they were a tenderfoot. I made similar mistakes as a beginner, paying too much for too little for things I didn't know I didn't need.
Heroku saves a lot of time for the 1-2 dynos ($25-50/mo) you need to vet your idea. With free Cloudflare SSL termination and a $5/mo t2.micro Postgres database, what else do you need?
For comparison, my somewhat popular forum with 257 online users at the moment and 300k req/day runs on 2 dynos. $50/mo for the application servers + a deploy/config solution is nothing.
The curriculum called for using Heroku but I regret following it now. Heroku bills itself as being easy for a beginner but go ahead and try to deploy any simple Rails or Node project using their guides. Half the time something goes wrong. Either you need extra dependencies or you have to do extra configuration that the setup instructions didn't mention. In the end you have to look up how to check the logs and even if you get that far a beginner has no clue what those logs are really saying. Even as an experienced senior developer, I couldn't get the demo project I was showing them deployed without a ton of hassle and 4 attempts.
So while it may seem like a VPS has a lot more moving parts, it's a better deal overall. Same level of confusion and complexity for students but in the end they at least know a bit about how a server works (which Heroku hides) and it's way cheaper even with SSL. I could have run that same project for $30 up front and $10 monthly.
The asset pipeline in rails use to cause some issues but I think that has all been resolved with the 12 factor gem.
Also setting up a VPS is in no way easier than Heroku. You have to install nginx, ruby, mysql etc. Then you have to setup routing. Then you have to learn all sorts of sysadmin stuff so you don't get hacked. Setting firewall permissions, mysql permissions. Then you want to deploy that app. So you have to setup capistrano or whatever. Next thing you know day wasted.
Heroku?
git push heroku masterThat's not the "right way" but arguably nor is using a Heroku box with no idea what's actually running on it.