My Self-Hosted Life
webworxshop.com
webworxshop.com
That's why I would love if a company like Mozilla, that offers stuff I support like Firefox, started offering a paid "Google suite" with custom domains. Or at least e-mail and storage. I understand most of it is a race to the bottom but it might be viable if it was open source, community driven. What I care about is knowing my data is not being sold and paying for not having to monitor logs, update servers and all of that.
I do use the cloud but only for encrypted tar files.
I do know about alternatives like the ones listed at privacytools.io, but it's all about trust (in before someone tells me why I shouldn't trust Mozilla).
Have done similar myself, trying to make the most of low-resource software to run on low-powered hardware.
Self-hosting email, while a PITA at times (must use mailinabox next time... but spf, dmarc, tls everywhere wasn't too bad to set up, just the multiple accounts were fun) is extremely satisfying. And no, it doesn't mostly end up in a gmail inbox. But even if it does, Prism leaks resulted in Google de-pwning themselves (internal encryption), supposedly. For now, etc.
Otherwise RSS (newsbeuter), XMPP (finch), email (mutt), IRC (irssi), Drupal with nginx + php opcode caching + microcaching, Hugo sites with nginx, letsencrypt/certbot. SSH tunnels for socks and remote connections. Cheap router with tomato firmware... Quite amazing what you can run on a pi, router and low end VPS with a bit of time and effort.
Even transitioning much of my word processing to markdown/latex/pandoc for dead simple clean and quick publishing.
I may be completely deluded, but for me the future is still the command line, low powered hardware and FOSS. Its strength is in its fluid development that seems able to endure decades of change and advances, weathering rises and falls of shinier things.
More power to the OP, may many more share their non-shiny setups.
https://github.com/piwik/piwik/issues?q=is%3Aopen+is%3Aissue...
Includes an issue from January about insecure random-number-generation: https://github.com/piwik/piwik/issues/9473
and one from March claiming that it doesn't reliably use TLS to update plugins: https://github.com/piwik/piwik/issues/7582
It bothers me a lot when people advocate self-hosted services with really bad security posture to increase privacy (or "control", as the author says).
But for example Piwik's main competitor is Google Analytics. It's reasonable to not trust Google for privacy reasons, but Google employs one the largest security teams in the world and produces very well-regarded research. I trust Google with securing Google Analytics more than I trust Piwik's developers with securing Piwik.
I applaud him for denying money to an industry that doesn't deserve it
And administrative incompetence? Dude had his server temporarily overrun with traffic. C'mon.
As far as competence goes: you're submitting yourself to Hacker News and your Wordpress site isn't caching content? Yes, that's incompetence.
But computin' is such a big field...
The best part is, though? For all his very manly self-reliance, this blog of his is on a DigitalOcean droplet. He isn't "denying" anything to anyone, whether they deserve it or not (and that's a laughable sentiment in your OP anyway, while we're at it).
My sentiments remain. I want a world of self-reliant experts, not halfwitted idea-people who see technology as a means to an end. That may not be this world, but one can dream.
PS: He admits as such in the blog that it is hosted on a VPS. And no one person is going to be able to step to another on every possible criteria. (Frankly, I read your high-school 2005 PHP staticize story with probably the same eye-rolling you gave that dude, cause i was building static HTML in elementary school in the 90s and was doing dynamic flash sites before AJAX became a think in the mid-aughts... and the dude sitting one cubicle over would roll HIS eyes at me because he used to program simulators and missile code for the military in the 70s and 80s. Holier-than-thou can backfire)
Setting up mail is easy. Setting up a web server that doesn't go down under medium load is easy. If you want to lecture others about this sort of thing, you had best come correct. Because those of us who do--and who especially those of us who are capable of using tools hosted in either our own racks or Amazon's without trouble, who are likely to have a problem with the shitty virtue-signaling in his post--will call you on it. Because the world is not so simple as to scream that "SaaS is bad!" and, sometimes, there are economics of scale worth leveraging. There is no virtue in refusing them; there are places for self-hosting and there are places for cloud systems and ascribing the rise of cloud services to "halfwitted idea-people" is a sign of a profoundly juvenile understanding of both the technologies and the economics involved.
Also running the database, webserver, mail server, etc. off a single machine is just asking for trouble.
nginx, PHP-FPM and APC, your caching tool of choice, done.
Sounds like "now you have two problems"? There is plenty of blog software out there but very few are so terribly, terribly slow as Wordpress. I'm pretty sure it's the slowest thing I've ever installed on my server (and uninstalled, obviously). Just use something else and there is no need for caching in the first place.
If anything, moving to an unproven blog framework is going to cause much more headaches than a worpress blog slowing down for seconds every time you make a post.
Until five years ago I ran that* on an old 2001 laptop with 128MB RAM, of which about 56MB went to Windows XP. Worked quite fine really.
* That, plus FTP server, SMB, DNS, VNC and uTorrent. I think that was all.
It's not like many other professionally hosted websites haven't done the same over the years, and my data remains in my control even when my website is crushed under the weight of enthusiastic visitors, so my self-hosting goal would be intact.
You could also look into librevault if you're interested in pursuing this avenue.
It's hard because you have to really be on top of security, but it's worth it.
> You might say that this is a bit of a cop out, since this all runs on a virtual machine, which itself runs on someone else’s computer. I would agree, however it’s a nice middle ground between going all out with your own servers and running everything in the cloud. To me the reality that the VPS is in the cloud is obscured by the ability to control every detail of its running software.
Hmm. Contrarily, this part convinced me to completely self-host all aspects of my internet life.
Also, sorry about your blog going down! What was the cause of that?
I understand the desire to take control, and have been on a similar kick lately to reduce my dependence on The Cloud. But I'm not an experienced network or system admin and I'm not concerned about using Someone Else's Computer when it's convenient for me. What I am worried about is my data being locked in to any particular service or being a pain to migrate somewhere else if I want.
I've also been documenting my progress, if anyone's interested. It's on a not-self-hosted-but-still-extremely-portable GitHub Pages site: http://ajashton.ca/decloud/
As someone who hosts a lot of his own stuff, that's the real selling point of cloud hosting. Not having to care about things like spam filtering, or how some blog you want to publish is going to scale in the face of unexpected traffic.
The entire point of using cloud hosting is to pay money to not have to care about stuff like that.
Yes, plus a bunch of engineers keeping the thing running.
That phrase, "just someone else's computer", has long seemed to me a piece of recklessly dismissive arrogance. Engineering cloud-based systems is simply not the same as off-cloud, and assuming otherwise will lead to dissimilar outcomes.
I mean, why don't you let experts do what they do and you spend your time doing what you do?
Unless you do servers. In that case, sure. Whatever.
But to suggest that everyone should do (or will do it, as some people are commenting here) it is bananas.
I never said that.
The implication in your original comment is quite clear, "why don't you let experts do what they do and you spend your time doing what you do?". So, you actually did say that... But to suggest that everyone should do (or will do it, as some people are commenting here) it is bananas.
The comment you replied to didn't suggest that everyone should self host, it simply stated a preference. Your comment, however, was the exact opposite, and suggested people shouldn't self host "unless they do servers"Personally, I self host services on IaaS (Vultr). At least then I have full ownership of my data, and it guarantees I'm running on open source software that can be modified for data extraction at any time.
But the smart people are proving again and again that they are not worthy of our trust. They find bigger and better and stealthier ways to learn about us so they can influence and move against us in the future. Why should we trust anyone who sees us as a product?
I'm not sure I agree with your version of the future. People don't know enough ( and don't want to) about security, scalability, availability, etc.
I think, mainly, because life is more interesting when you do things you are not an expert of.
I can't afford a wide pipe, I can afford Digital Ocean.
If I want to spin up a server for a day or two it's much more economical to pay for a virtual server than buy one and install it in my home.
The clincher for me is email. I'm happy to configure and run a web server, maybe with a caching reverse proxy, couple of synced db servers, whatever. But configuring email just isn't worth it - I've tried. Whilst it can be setup the big players in email seem to regularly blackhole you 'just because' anyway. So the amount of time in setup and servicing just isn't worth it for a handful of domains (basically me + immediate family) unless you've got time to waste. It if a good learning experience, and I do like the control, particularly over span handling.
Even using a (small) ISP, having DKIM and SPF setup, mail sent, even as a reply, still gets spam binned often by Google, Live, be etc..
Practically it just doesn't seem to be something to do on your own.
It did take some time at the beginning to get all of the DNS stuff right, but that's a one-time cost. And, so far, I haven't noticed any spam binning once I finally got the DKIM & SPF stuff correct.
I guess part of it could be that since I'm using a lesser known ISP my IP hasn't been blacklisted as part of a large block.
If you still have an interest in self-hosting email, I highly recommend Mail-In-A-Box (https://mailinabox.email/).
For those that know me, I’ve made no secret of the fact that I believe that you are better off doing something yourself than outsourcing the task to someone else, especially in areas that you are interested in or have some expertise. For me this has particular value in the case of my computing. As a result, I have taken the decision to self-host as much of my online services as possible, rather than relying on the cloud (since that’s just someone else’s computer). I’ve been working on this for years (actually the whole time this blog has been dark and before) and at this stage I’m mostly there: almost all of my digital life is provided by Open Source software, running under my control.
This post will detail what I’m using and how it all fits together. I’m not going to go into technical specifics since otherwise this post would be huge, perhaps I’ll focus on some of that in future posts (feel free to make requests in the comments). Also, please note that my setup is by no means finished and probably never will be, it’s an ongoing project and it has become pretty much my main hobby to install and maintain this stuff. In the Cloud
I’m going to start right here, with this blog, since that was where the whole thing really started. This blog existed well before my undertaking to self-host. In the early days it lived on a shared hosting plan provided by Dreamhost. The site has always run WordPress, although I’ve toyed with the idea of moving to a static site over the years, I’ve just never quite managed it. In 2011 I moved the site to a shiny new VPS provided by Linode, where it has lived ever since. There is also a Piwik install for tracking website stats (which I’ve blogged about before).
The main motivation behind the VPS was to install and configure my own mail server setup, something which I ranted about shortly after. This setup has be serving myself and various family members well since then, with really very little maintenance on my part (almost everything is automated).
There have been various other uses for the VPS over time, many of which haven’t stuck. Probably the most successful has been an installation of TT-RSS, which started life on my home server and at some point moved to the VPS for convenience of access. I’ve also dabbled with various chat applications, mainly XMPP based, but they’ve never really been that useful due to the network effect of no-one else using them! At this stage email has become my primary form of communication.
You might say that this is a bit of a cop out, since this all runs on a virtual machine, which itself runs on someone else’s computer. I would agree, however it’s a nice middle ground between going all out with your own servers and running everything in the cloud. To me the reality that the VPS is in the cloud is obscured by the ability to control every detail of its running software. Its also pretty nice for services which I want to be reliable, since Linode almost never skips a beat. At Home
So the VPS is one thing and is really used for critical services or stuff that needs to be accessible to the wider Internet (like this site), but the real magic happens on my home servers (yes, there is more than one). My main server (now on its second hardware iteration) started life as a MythTV system and still does a great job in this respect. Many other services have been added over time, such as an MQTT broker (mosquitto), git server (gitolite+gitweb), a calendar/contacts server (Radicale) and file synchronisation (Syncthing). At some point I also switched out the MythTV frontend and replaced it with XBMC (now Kodi).
In the last couple of years I’ve been moving further down the home automation route, rather than just sensing and logging via MQTT. I’ve finally settled on Home Assistant as my automation controller and UI, along with an instance of Node-RED to do some miscellaneous processing. This all runs on the main server, with a Raspberry Pi 2 in the garage functioning as what I like to call ‘the gateway’ (it has a couple of radios and some sensors connected and runs another instance of Node-RED to shuttle this data to MQTT). In addition I have my home CCTV set up using a couple of webcams and MotionEye. One of the cameras is located remotely and connected to another Raspberry Pi (this time an old model B) and streams back to the main server with mjpg-streamer.
I also run a pfsense based firewall to protect my network and provide remote VPN access. This runs on an old netbook with an extra USB ethernet adapter. The internal network is partitioned using VLANs to provide a separate firewalled subnet for the home automation gear, some of which is cheap Chinese stuff which needs to be forcibly prevented from talking to the cloud. The networking gear consists of two TP-Link routers, flashed with OpenWRT which provides nice VLAN support. These have been configured to just provide switching and wireless access points and delegate all the firewalling, DNS and DHCP stuff to the firewall.
Within the last year or so I’ve been working on streamlining the management of all of this. The principle focus of this has been monitoring all the services I’ve got running. For this I’ve settled on Nagios, which I run in a separate VM hosted on the main home server. Although complex to set up, I can’t talk highly enough of Nagios, it’s brilliant and it saves me so much time just by knowing what is going on on my network. Email notifications from Nagios of course go via my own mail server! I’ve also played around with collectd, InfluxDB and Grafana for performance graphing, although I’ve yet to deploy this to everything. Conclusion and The Future
So that was a probably non-exhaustive list of my self-hosting activities. I’m sure I’ve probably forgotten many things and of course there are the huge amounts of supporting software that I haven’t mentioned. As I said, I’m now at the stage where this meets almost all my computing needs although there are a few areas where I want to improve.
The main thing is automating and persisting my configuration, since I’m still mostly doing things manually. For this I’ve settled on a combination of Ansible and Docker. I’ve played extensively with both but haven’t really made much progress with deploying them for much more than testing purposes.
I’m also constantly evaluating new software to fill gaps in my ecosystem. I’m currently looking at Rocket.Chat and Hubot to provide a chat based interface for remote administration, but don’t have a usable system yet. I’m also toying with the idea of a Gitlab server to replace the gitolite+gitweb system and to utilise the CI in my automation strategy, but I’ve heard it requires a bit in terms of resources (incidently gitlab.com is really the only 3rd party service I heavily use).
That I am able to do this at all is a testament to the power of Free and Open Source software and cheap commodity hardware. I find it pretty awesome to think that almost every interaction I have online utilises my own infrastructure and that it works tirelessly for me 24/7.
I’m only just getting started documenting my setup here, for instance this post hasn’t touched on any of the client applications I use on my phone and desktop machines. I’m also going to do some more technical posts on various aspects as time goes on, so please stay tuned (or even subscribe to the RSS feed or mailing list!).
My Self-Hosted Life
"Error establishing a database connection"
I think this may have been one of the more unintentionally ironic and hilarious blog posts Ive seen in awhile.While I run my own server for some personal projects I'd never advise people to do it unless they absolutely have to. The maintenance, security updates and embarrassing events like these for the most part are not worth it.
Edit: Besides, the article mentions "the VPS is one thing and is really used for critical services or stuff that needs to be accessible to the wider Internet (like this site), but the real magic happens on my home servers". That isn't the self-hosted part anyway. /end of edit.
> I'd never advise people to do it unless they absolutely have to.
I'd compare it to work. When doing a project for a client, all else being equal, you'd rather have them pay a bit more so you have more time to develop a great product. Rush jobs are never fun and you usually have to cut corners. If you can make your code nice, it can be made flexible and neatly extendable.
Same for hosting: yeah it takes a little more time than getting shared hosting, but it gives you so much freedom to install and configure your own software. Save for perhaps mail servers, it's pretty much always worth it in the long run if you can afford it in the short run.