EPYC Server Configuration
hetzner.com
hetzner.com
> Consulting service: you bring your big data problems to me, I say "your data set fits in RAM", you pay me $10,000 for saving you $500,000.
Previously, the cheapest such server was 700 USD at OVH and it only included half this much of NVMe SSD.
Also, I gave a talk years ago at NYCCamp trying to hammer in that most websites do not need all the scalability tricks as they fit into a single server. Well, this server can happily house a 7TB database on mirrored SSDs and that's still below 500 EUR (with "only" 128GB of RAM). You need to think very hard whether you need to shard, cluster etc.
They read on the internet that the only way to survive FB levels of users is webscaling, and they won't make a bet unless they think you'll be FB sized in three years.
This one is under $2K:
Don't forget to add two 960GB U.2 NVMe drives. Those are expensive. For eg https://www.neweggbusiness.com/product/product.aspx?item=9b-... $831.60 apiece. Doubles the server price. Oh I forgot you picked a server which doesn't have hotswap NVMe bays...
Also that CPU is old and slow. It is the one before Sandy Bridge. I can't find the EPYC chip on the spec site but a roughly comparable Xeon:
Old: https://www.spec.org/cpu2006/results/res2011q2/cpu2006-20110...
New: https://www.spec.org/cpu2006/results/res2017q3/cpu2006-20170...
(yes, the latter is 2P so you'd need to halve it, it's still twice as fast)
Had a CPU cooler fail somehow (resulting in one very toasty, unstable server) and they responded within minutes, the whole thing was probably resolved within half an hour.
Regarding grandparent: What kind of hardware failure? I had to change different types of hardware in the past. For HDD changes you send a full SMART result + possibly the logs showing that the RAID kicked the faulty disk and they replace the faulty disk in 30 minutes (and one time even apologized that it took 2 hours for a low-priority-support server). In all cases the actual downtime was < 5 minutes, because of RAID. For possibly broken fans I simply stated that according to my Munin logs show consistent temperatures near the upper limit and asked whether they could take a look. They added an additional fan within 30 minutes, again with actual downtime < 5 minutes.
Most of my replacements were during the night in Germany, that might have helped, because there are possibly less requests in parallel. And I always had hard logs proving my HDD failures.
https://techcentral.co.za/hetzner-hacked-customer-details-co...
https://techcentral.co.za/hetzner-deeply-distressed-data-bre...
Super nice, responsive support too. I've had their Head of Product, Arno Pirner, engage in a long email exchange when we inquired about GPU servers last year (they finally launched a GPU line recently). Great service.
The advantage of cloud stuff is if you need an extremely high amount of power for an extremely short amount of time. For example, I needed a hundred CPU cores + TB of RAM for a 15-minute time span, paid less than 100$ - renting this or, god forbid, buying this, would have racked up 10k+ bills for sure, for buying probably over 200k.
Once you have base-line load that can't be served with micro/mini instances, there is no financial alternative to renting, and in some cases buying+colo may come in even cheaper (but requires HW maintenance personnel).
Snapchat, for example, pays 2 billion dollars for 5Y to Google, equivalent to 400M$ a year (per http://www.zdnet.com/article/snapchat-spending-2-billion-ove...) ... I wonder what their CFO (or any board member who approved this) has smoked. No way this huge amount of spend is justified - not even the taxing differences between capex (buying) and opex (cloud/renting) can justify this in any way.
In addition, all cloud providers charge heavily for data egress, which really makes me wonder how on earth a service like Netflix can actually be profitable.
To sum it up, everything outside of "the play button" is on AWS. This includes billing, account management, et al.
https://www.hetzner.com/news/neuer-dedicated-root-server-ax1...
Other than than it has neat-perfect value per dollar.
Pricing: https://wiki.hetzner.de/index.php/Root_Server_Hardware/en#Mi...
Excerpt:
> 10 Gbit Intel network card: € 13.50
> 12-Port 10 Gbit switch: € 43.00
In about a month I had a handful of days where I wasn't having issues, half the time I'd open a ticket, report a problem then a bit later get "yes, we are looking into that now".
Left a bad taste, these days I just use linode for most things, if I needed heavy duty processing power there are some decently priced options near to me (bytemark is about 60 miles away from me).
which is about 8 times as much, with nowhere near the throughput.
I assume with reserved one could knock it down to ~$650
Assuming it's perfect, and you push it for a full month, AWS egress charges for that 328 terabytes: $20684.
Because of their four dual-channel memory controllers, EPYC CPUs support eight-channel RAM. So, for optimum performance, it would need twice that number of modules, right? I don't know the performance differential.
80% of threats and DDOS attacks we receive come from Hetzner IPs! We stopped wasting time reporting this to Hetzner and simply block whole IP ranges in Cloudflare. Sad but true.
You'll lose customers that way.
It's like rejecting email addresses that don't end with .com.
There are lots of services these days that can "smartly" handle DoS attacks (e.g. only drop traffic from an IP in the range when it starts flooding you).
Maybe someone runs VPN's trough them?
You see Kaperskys IPS on your logs and wonder...
In any case, we only block for a few hours.... and yes, you definitely risk losing clients. I know Hetzner is not only DE based and many user cases for IPs originating are possible, but luckily DE is not our market.
Sorry, this doesn't sound believable in the slightest.
We get hit everyday by 1-2 intrusion attacks as well as a few DDOS a month...and the intrusion attacks are mostly from anonymised address or singled-out ISP IPs...but of the ones that come from Cloud based organisations, 80% or more is Hetzner.
We've never seen attacks from AWS/Google Cloud/Rackspace, etc... but Hetzner shows up in our logs a lot.
Probably because people renting servers from Hetzner, OVH and friends run them once and keep them running without upgrading the OS and software which means they will get pwned (and a pwned hexacore server with 1 or 10Gbit gives you pretty good resources compared to an AWS micro instance)... while AWS disincentivizes you from doing so. In addition AWS tries to enforce security with its heavy reliance on security rules, which adds another layer of security - after all no one can hack your mysqld when it's not exposed to the Internet...
Range blocking is a really silly thing to do don't you think? Hope you guys find a better way that that. Something tells me your application might be leaking your site's IP?
Although cloudflare has also a Web application firewall, somethings always slip thru.
Re: range blocking, only very specifically and when it got out of hand...and just for a few hours. Not a good solution, I agree