Building a fast, secured and free static site in less than three hours
fillmem.com
fillmem.com
- It's free (though you can become a supporter and get some extra benefits) [1]
- It's fast, since it uses it's own CDN. [2]
- It's secure, all pages support SSL, even with custom domains. [3]
- It has a command line tool [4] that can be wrapped to automate upload of pages, or used in a Git hook.
- It has a plethora of learning resources [5].
[1] https://neocities.org/supporter
[2] https://www.youtube.com/watch?v=-i6wvix6buI
In terms of deployment, I use Caddy which, with ~3 lines of config will auto-TLS your site using Lets Encrypt, and handle renewing the certs for you each month. Caddy also automatically pulls your changes, builds them with hugo and deploys them with ~2 more lines of config.
It's the easiest solution (as a developer) I've come across where I just commit to Github and my blog is updated, and Caddy deals with my cert renewals.
Edit: Not sure why this has been met with a stream of downvotes. Is there something wrong with saying "I use a different approach to publish this blog: [link]," especially if it's technical and would be of interest to HN anyway? I see many people do it constantly, even when it's not relevant to the article or discussion at hand.
Edit 2: I don't generally care where a post is but this went from -2 to +6 pretty quickly. Weird?
Are you feeling picked-on because of what you're saying, or how you're saying it?
So I’m reducing my activity on HN in general as far as possible, and only post as uncontroversial opinions as possible, because I fear that going against the established opinion would just get me downvoted again.
This is a common occurrence. Written communication involves both the writer and the reader(s), and unfortunately that results in losing other channels of communication such as intonation and body language. I think written communication is a skill that can be improved with purposeful practice if you think it's worth your time (and to be fair, whether or not one considers posting on HN personally valuable is not a given :).
It sounds like it's at least a little important to you. I personally think the effort is worthwhile in general, as it's useful to know how one comes across in various media, and particularly if you feel you have something valuable to contribute.
I've got a few resources in my profile that I find useful to return to—and have, repeatedly done so to deepen my internalization of them. I'd encourage you to take a look and see if they might be useful to you as well.
Edit to add: I hadn't read this entire thread before responding. 'mikekchar has captured a lot of what I also think about in their comment here:
Where is the reason that ever of my comments in that comment chain was originally voted to -4?
I jist don't get it. It's not attacking anyone, providing additional information about the parent comment, and factually correct (as another user even provides a cdc source later on)
The primary issue I see here is that it's an iPhone thread on the day of an announcement. Emotions are going to be even higher than normal and I always take extra care when entering such waters. I remind myself that effective communication takes two parties, and this particular ground is already seeded with land mines.
Questions I'd ask myself, even of facts:
Is this worth saying? Does it add to the discussion? How much does it add to the discussion even if I am able to couch it in the best possible way? Am I correcting someone? How do people react to correction, even if I'm right? What is the reaction to the least charitable reading of what I'm posting? Am I on topic (both in the subthread and the submission)?
Putting on my most uncharitable hat here, I'd say this subthread starting with 'xvolter's comment was doomed from the start.
https://news.ycombinator.com/item?id=15230968
It can be read as nitpicky, needlessly negative, and incendiary (likely to evoke a strong, defensive emotional response). The lead-in "Are they aware" can be read as very condescending. I haven't read up on the iPhone release, but I suspect Apple used the phrase "surgical steel" to describe some component of the iPhone. To take them to task for that is pedantic. It's marketing speak. You have to expect some level of exaggeration. Even if it's technically correct, what is this correction going to contribute to the thread on iPhone X? Is it likely to create constructive discussion? From what I've observed, some HN members will down-vote such comments and those in the subthread even if they're correct because it's not constructive to the overall discussion. And flame wars not only are destructive in their own thread, they tend to poison the entire forum as it promotes needless argumentation. Don't get me wrong: it's easy to get caught up in such a thread, thinking "Look, once I point out this, it'll be resolved. It's just a clarification. I'm just trying to help." I know, because I've been there.
Also note that even if this is not exactly what was going on in any one down-voter's head, it's useful in that it gets me thinking about how it might be received and generally how I can improve my comment—which might mean not commenting at all.
To put this even more personally, thoughts that have been going through my mind while composing this post:
- Gosh, this is getting long. I'd really like to tighten it up. Is it worth the effort? How much time should I take reviewing and editing it before posting? (After writing but before posting I'll be sure to review the entire comment, but I know I'm not going to tighten it up much because I'm tired.)
- What I've written can easily be misconstrued, particularly because I've written things that are uncharitable, even though I've put in the disclaimer that's what I'm doing on purpose as an exercise. It's late, and I know I haven't thought through everything or the entire thing very thoroughly. I know that in and of itself opens it up to misunderstanding. Are people going to misread what I've written because I've left something out? Is the possibility of that miscommunication greater than the value the post is contributing?
- I'm particularly concerned about my explicit, uncharitable reading of 'xvolter's comment and the response to the entire subthread. Is it necessary to include this for my comment as a whole to be effective? Can I write the comment while excluding it? How much time would that take? I'm leaving it in because I think it is useful and on balance, really, what does it matter in this single instance? (But it does matter, on some level. It's a reflection on me.)
I'll end up clicking "reply" because I think you've put yourself out there and sound like you're sincerely looking to improve your writing, and that's worth the effort. I also think that it's clear that my intent is clear and good, and I'm know I myself am still learning: if there's some negative reaction to this, I'll take that and use it to improve my writing next time. I certainly know I've got more to learn :)
In sum: it's a volatile submission, it's an off-topic subthread, and getting involved is fraught with danger.
Wow. Did I really need all of those words if that short summary is all there is to it?
That's impossible to answer without telepathy.
(Aside from topics that generate lots of discussion that weighs one particular way, I find it impossible to determine a priori whether a particular viewpoint is controversial on HN. For instance I have recently and wrongly predicted that transhumanism would be uncontroversial; and while I've noted this as evidence for future predictions, I am unable to explain it logically.)
For me, the vast majority of down votes come from me being wrong (that is, I post something that I think is correct; I get down votes; I do more research and discover that I am, indeed, incorrect). In fact, this is such a good flag for my writing that when I get a down vote I immediately assume I must have made a mistake somewhere and start looking for it.
The next most common source of down votes (for me) is being argumentative. If I get a down vote, but decide that I am correct, I often discover that the tone of my writing is derisive. In all honesty, I never intend to have this tone of writing, but I am human and sometimes (either through lack of writing skill, or by unconsciously being an ass) it happens. My guess is that the person I'm responding too gets pissed off and down votes me. This has led me to have a kind of rule to try very hard never to piss off the parent poster, even if I think they are wrong. If I can't think of a way to comment without pissing off the parent, I try not to post. As a huge bonus, this avoids me getting dragged into >90% of trolling efforts (a statistic that I made up).
The next most common cause of down votes for me is lack of coherency in the comment. Sometimes people simply don't understand what I'm saying. It is important to realise that as a writer, you can't assume the readers understand what you are thinking, so this is completely down to you. Trying to put yourself into the role of a random reader and figuring out what they might think when they read your post is hard. However, this is what being a good writer is about. Again, if I write a post and upon reviewing it, I don't think most people will understand, I don't submit it.
Related to the last point, there are lots of times where I have relatively unique ideas. Very frequently people will not know what to think about them because they have never really explored that way of thinking. If I write in a way that makes it clear that I assume that the reader will find what I'm saying is obvious, I will get down votes. In a way it's insulting to say something that is not mainstream and assume that others will instantly understand/agree. Sometimes, if I feel the idea is interesting, I'll still post, but I'll try to broach the subject gently/apologetically. People are doing me a favour by getting out of their comfort zone and considering a different way of thinking.
Finally, when I'm posting, I often pick someone to respond to and try my best to help them. If I am successful, I find that the post is usually highly regarded by many people, even though my focus is only on helping one person. YMMV!
> The next most common source of down votes (for me) is being argumentative.
Interesting. The main thing that motivates me to comment here - other than when someone touches the surface of a topic that piques my curiosity - is when I see something that is either blatantly wrong, or seems to be missing an obvious piece of clarifying information.
(Examples of wrongness: C# is the best language one can learn, any random non-MBA-holder can be given a loan and expected to make a successful business of it, random 6-year-olds can understand CS, one person without political office can make a difference among our population of 300 million, etc.)
There are times when I feel I've done my best and the thread doesn't seem to be progressing well. When that happens I take even more time to see whether there's any way I could have approached it better, and restrain myself from having to put in the last word. Effective communication does take effort on the part of both parties. If I feel I've done my best and conclude it's not working, setting it aside is often better than persisting and possibly making the discussion worse.
If someone can't understand a simple list of facts unless it's couched in ... literature-course fluff, I suppose it could be called? ... then that's their problem and they're accomplishing precious little by foisting it onto everyone else.
> And I generally feel happier as a result. In turn, writing when feeling happier results in better comments. A virtuous circle.
Interesting. I find that happiness tends to dull my wit, make me less observant, etc. While it's not unusual for me to recall a long-past conversation (from any medium) and suddenly formulate a much better response at some particular junction ... feeling happy or contented tends to increase the probability that a current conversation will result in this sort of after-the-fact second-guessing.
If they don't take it in the way I'm presenting it, it's my responsibility to evaluate if there's a better way I can present it. Upon reflection (and that can be short or long, depending on how important it is to me), I can reasonably decide it's not worth the effort or time to do so. I can also come to the conclusion that perhaps the audience isn't really open to listening to what I have to say. That said, laying all of that on the audience without reflection in my experience is a recipe for failure and frustration.
edit: I'm working on being able to handle being wrong... usually flip out, like WHAT!!! You disagree with me?! (Contrary to my initial point about no bs)
One cannot "construct" anything from a foundation that is so thoroughly wrong that it crumbles at the slightest touch.
Is it then so wrong to give that foundation a hardy poke, rather than making a vain attempt to "construct" something atop it?
Probably I can answer that :) I noticed that when one of my posts get down voted even when having a neutral comment, it swings back to positive fast when touching -1 or -2. I guess that the gray comment takes a while for HN'ers to notice as down voted. And when they find that there is nothing wrong with it or they actually like it, many people simultaneously click the upvote swinging it back wildly to positive zone. It is HN's own version of 'universe making right what it deems as correct' :D
TL;DR: I think it would be a big mistake to [...] outlaw downvoting for disagreement - dang (HN mod)
I've also seen many of my own comments go up and down quite a lot as the upvoters & downvoters battle it out. (Eventually they tend to settle on a solid "meh.")
I'm not sure how that's easier than GH Pages or Netlify and both of those have the bonus of being free, HA and don't require that you monitor anything for uptime.
The main differences on mine are:
- I use Jekyll, which is ranked #1 in the static site generator space.
- Hosted on AWS S3.
- CloudFront in front of S3.
- Routing and aliases handled by Route53.
- Deployed using a tool called s3_websites (change detection only uploading generated files AND cloud front cache invalidation for only the changed objects).
- Coded in a Docker container via a cloud IDE called c9.io using the Ruby template.
- Generator and site files committed to a GIT repository hosted on AWS CodeCommit.
I still use Jekyll too. It's awesome. It powers my main site (about 100 posts) and builds "fast enough" where it doesn't get in the way.
Although I use DigitalOcean and use Ansible to build / deploy the site. A couple of lines of yaml lets me deploy a new site with HTTPS (using Let's Encrypt).
Another very nice piece of the puzzle is TLS certificate management using Amazon's ACM. It's no cheaper than Let's Encrypt, but it's a lot more convenient. You put it in place once, and you never have to touch it again — Amazon's engineers will deal with hiccups and bugs instead of you. It's no more convenient than CloudFlare, but I like to minimize the number of services my dependency graph.
Kids today.
You must be a racist if you can't see that.
If you can't contribute, leave.
Now I use vim.
We routed console direct to disk in PR1MOS, and if you made a mistake, you had to start all over. But you never knew if you made a mistake until it was done because you couldn't see the output as you typed.
Of course, you didn't end up with a web site, but the result was globally networked. As long as you didn't mind that e-mail took several days to get across the country and a week to go from Illinois to Sweden.
/!killer!jolnet... /Bang paths FTW!
* by "good", I mean the following:
- prose is engaging
- very comprehensive, no hidden steps missed
- covers a lot of things that while not strictly necessary, will make an experienced git user's website updating workflow much easier in the long run
- covers some small details that are new to me that look nice
It's very much complexity up front in exchange for automated ease later though.
From the outset it is version controlled, CDN'd, available over HTTPS, and would withstand being linked from the front page of HN just fine.
It's not just a static site, it's one that is easy to grow and modify, and that can withstand a lot of traffic immediately with no investment in infrastructure for the author.
(evidenced by the fact that it is withstanding a HN front page set of traffic)
Or more popular, you could do it with a horrible WYSWIG editor which output garbage (Frontpage express).
Beg
I remember getting pissed at DW making 600kb files, but hand-rolling it brought it down to ~200kb.
Ah, life on dial-up, when those bytes mattered.
https://www.jgaa.com/content/1/old_sites/july_2000/htmgen32....
This article seemed like a good start, but I'd love to know more about how you built your blog in a way that's easily maintainable.
# install cowsay, and move the "default.cow" out of the way so we can overwrite it with "docker.cow"
It is possible to make it more secure by changing the setting to "Full SSL (non-strict)", which encrypts the connection between Cloudflare and GitHub against passive attacks but not active interception. Unfortunately, GitHub pages does not work with Cloudflare's "Full SSL (strict)" option.
Cloudflare SSL Options: https://support.cloudflare.com/hc/en-us/articles/200170416-W...
Example of attack between Cloudflare and origin: https://medium.com/@karthikb351/airtel-is-sniffing-and-censo...
GitHub issue page: https://github.com/isaacs/github/issues/156
GitHub pages are amazingly fast and a pretty good default choice. With cloudflare it's a pretty solid combo.
But netlify's awareness/integration between the content and the cdn is really compelling. Imagine they'll be able to do a lot more with it down the line too.
Built-in continuous integration and automatic SSL, you can even get your domain through them. Their CMS makes creating a fully featured blog ridiculously easy. 10/10 would Netlify again.
Turns out, the easiest path is Netlify. It provides you with a CDN and storage for free, and has a nice drag-and-drop deploy interface for basic static sites.
I use Hugo + Gitlab + Netlify (free https). I use Emacs as my development environment, and Magit (https://magit.vc) has come as a boon to me. All the git shell scripting mentioned in this post reduce to few key strokes with the help of Magit. I'm not intending to divert the topic, but couldn't help mentioning that the Magit Kickstarter [1] needs some love.
Coming back to the Hugo topic, I believe that the 3 hours is a good practical estimate for someone who has never dabbled with git/github, domain control tweaks, CNAME, etc.
So don't take that 3 hour mention as a negative, and jump right into the post. Once you have the whole setup, updating your site is a simple git commit + git push (hardly a minute -- not counting the time it takes to gather content for a new post :)).
[1]: https://www.kickstarter.com/projects/1681258897/its-magit-th...
I've created an actual static site myself, but it takes a bit extra - especially from the theme.
Also, I don't understand why you'd use Hugo with Github when it already supports Jekyll?
I built my own custom static site generator (python + jinja2) for running my side project[1]
I just git push and Netlify picks it up. Simple, to the point and no JS.
[1] I run https://discoverdev.io , a "product hunt" for top engineering blog posts!
WordPress is easy to set up, supports users and comments (if you want them) and has a lot of really nice features and plugins. WordPress is also slow and a pain in the neck to maintain, but I can understand why people might think the tradeoff is worth it.
I also run my site[1] using my own custom-built generator and I haven't looked back, but even I sometimes miss the ease-of-use that my old WordPress site provided.
- posts are rendered from markdown with syntax highlighting for code
- safe links to other domains (noopener and _blank)
- bundled CSS, which look good (or as bad) on mobile
- a PWA (the service worker is the only JS run client-side)
- pre-populated links out to twitter (with a card) and mastodon with tags drawn from markdown metadata
- HTTPS using a letsencrypt cert and a one-liner in cron.daily to update it when close to expiry
- a smallish nginx config focussed on security to serve files
Much of the generator is just glue code around some good modules. Some important things like safe links were hacked together by me.
(if you're interested, https://qubyte.codes, but I need to post more often)
Octopress was getting to be a pain in my butt due to ruby dependencies being awful to deal with.
https://news.ycombinator.com/item?id=10376468
> jack000: there was some interest in what I was using for the backend, so I cleaned up the code a bit
https://news.ycombinator.com/item?id=10794715
> hlawson: Expose looks very impressive
hat tip: https://hn.algolia.com/?query=static%20photo%20comments%3E5
> Github pages does not offer secured custom domain name. The best way to get this feature for free is to use Cloudflare.
[The article then proceeds on how exactly do that.]
[1] https://support.cloudflare.com/hc/en-us/articles/203349264-A...
+------------------+ +------------------+ +-----------------------+
| | | | | |
| CLIENT | +----------> | CLOUDFLARE | +---------> | YOU |
| | SSL | | NOT SSL | |
+------------------+ +------------------+ +-----------------------+Full SSL doesn't really protect you since Cloudflare won't check if the certificate is valid, an attacker could make their own self-signed cert and MITM you.
Full SSL (Strict) requires a valid cert for the domain being requested. If you had that, you wouldn't need Cloudflare in the first place.
Edit: Looks like you're correct. Sorry!
I will see what is required to swap something like the kube theme into this guide:
https://themes.gohugo.io/kube/#GettingStarted
"There are a few concepts this theme employs to make a personal documentation site.
It’s important to read this as you may not see what you expect upon launching."I'd just go for Netlify as well for hosting. It'll build Hugo sites for you when you push commits, they have a CMS you can connect with most static site generators, they deal with SSL setup for you and tons more features. Self-hosting anything eats up time and it wouldn't be as robust.
if (or cond1 cond2) (if (or cond1 cond2) (then) (else))
although i suppose it's not really hugo anymore.. (if (or cond1 .. condn)
(progn
(true1)
(true2))
(false1)
(false2))
But in Go templates, it would be:{{ if (or cond1 .. condn) }} true1 true2 {{ else }} false1 false2 {{ endif }}
Even though I know all the ins and outs of AWS, I really like this product for simple projects.
(I have no affiliation with Amazon)
- mustache(command line) + html
- Firebase hosting (superstatic)
I just install a command line version of mustache for example [1] and run it over simple static templates:
`mustache data.json myTemplate.mustache > output.html`
I only need to install superstatic[2] locally if I want to debug a rewrite rule or redirect otherwise clean URLs work pretty well with a simple setting.
Example: https://github.com/mizzao/andrewmao.net/blob/master/Rakefile
I have access to all the npm ecosystem. Is fast. No bloatware or weird code.
Styles with styled-components for easy maintenance. https://mateom.io
Deployed to an S3 bucket connected to CloudFlare.
I just type 'yarn deploy' and it builds my blog and pushed it. And I can commit everything to source control as they keys are in aws-cli
I see npm as the best source of slow, bloated, weird modules.
You can automate the uploading of files by writing a script to upload the files to the bucket so you can deploy in a single command (it gets trickier if you want to do a sync and delete files).
Personally I use rake [0] to create build and deploy tasks so I can do `rake build` and `rake deploy:prod`.
For my static sites, I'm usually doing some form of fancy JavaScript npm / gulp / bower, but then ultimately just uploading those files to S3.
You could probably do it a little faster using the AWS CLI. It can upload a directory to a bucket in one command (while skipping unchanged files).
I have nearly 0 experience with web-dev. I'd like to add some minimal user tracking to my static site on Github; just when & where the requests are coming from (geographically), which posts they're looking at and maybe a referrer.
I don't want to use Google Analytics (seems unfair given that I block it). Is there an easy way to do this?
Cloudflare is also a great free CDN and has a crap ton of edge servers to make your static content serve quickly around the world. Has a lot of other great features too.
Anycast ftw.
Quoted from the post. It's used for flexible HTTPS.
Curious why people want to serve static sites to users over https though.
... and I get it, one of our webdevs spits out static sites from some PHP code he wrote that builds them. As the guy that has to administer that crap I much prefer to hoist static HTML... but like so many things in the SV tech scene, these stupid "engineers" have to build a thousand different little frameworks with a thousand new buzzwords for a thousand unoriginal, rehashed ideas. Many of them forsaking old techniques that worked well, and in many cases better the cheesy little framework some fresh-off-the-boat bootcamp-grad "envisioned" because he didn't want to learn $UNFASHIONABLELANGUAGEORTECHNIQUE
EDIT: I just realized that's a question I should ask: Does your price include the domain?
S3 static hosting is far easier to manage than a virtual server; it's a trade-off of convenience vs savings.
I'm really conscious about the resource usage of my server processes. Most sites are static websites, but I also have Gitea, Prosody and Matrix Synapse running on that box, plus some small Go webapps for my own consumption.
I've used digital ocean droplets for some things for a similar $5 a month price, but it hardly seems necessary for a static site. It's much less faffery to just upload some files to S3 and click some buttons in the AWS console to configure everything.
I would simply install nginx and write HTML by hand.
If I felt fancy, markdown + pandoc. But if you feel like you need to put some content online, you don't need much more than a text file with some links.
It took me three months to rebuild https://www.forthepeople.com as a Jekyll site on a load-balanced cluster from WordPress.
? is actually for the query parameters and that's a properly-formed URI.
The user is expected to click the email icon, then fill in the to: address, with the body pre-filled with the current url.
Most email urls passing query string parameters fill in the address (which winds up in the to:) and subject instead.
That said though, best damn lawyer's site on the web, amirite?