I guess docker gives you some flexibility for rollover and load balancing, but a single droplet will handle huge amounts of traffic for static sites.
I guess docker gives you some flexibility for rollover and load balancing, but a single droplet will handle huge amounts of traffic for static sites.
I personally fell for these posts a while back and regretted spending time on it. They don't tell you about the crazy amount of sysadmin skills that you need to get it up and running:
Do you need to worry about updates/security patches? How do you configure firewalls? How do you configure ssh settings? How would you even audit unauthorized logins? Where are logs stored? Are they rotated? Are they backed up? Are there backups? How do you restore from backups? How do you configure nginx? How do you configure certbot? How do you check if cron is running correctly? Do you ever look at access/error logs? How do you keep services running upon restart? How do you get notified of problems? How do you monitor uptime?
Each individual question will take minutes to hours to research and will open up new rabbit holes.
Most {net,dev,sec}ops engineers aren't writing blogs.
Unfortunately, in my experience this is true. It's not for lack of motivation or desire, it's because my day job is stressful and tiring. The last thing I want to do when I come home in the evening is to spend my valuable personal time writing a blog about what I did at work. I would rather spend time with my family, or do something like that.
Of course, I could try to schedule time during work hours to write a blog on the company website by talking with my manager about it. Unless this advances any strategic or political agenda, it's unlikely to happen.
I write a post on my blog about my interests once every month or two, and maybe crosspost it to Facebook, but I like that I get to write down my thoughts on a site I own.
If you don't get much enjoyment out of writing period though, not much reason to blog.
I've found it useful for myself and colleagues, but also it's really awesome seeing hits from Google and other mediums where people are obviously finding it organically and sharing around through various means. Helping others find new / better ways to do things is really awesome
That's all part of the fun for DIY projects like this. Paying someone else to handle it for you isn't really part of the hacker ethos.
I set up DO to host a half dozen websites with a standard LAMP, NginX reverse proxy, and such. Then set up email with horde, spam filtering etc., then realised that managing all of that without breaking anything was going to be a pain in the arse. The web side is relatively straight forward, the email side was really fragile.
So I switched to a shared hosting account for about the same monetary cost.
Generally I enjoy the admin, but I'd be needing a duplicate test system to trial optimisations; a part-time hobby is then looking like a full-time job.
All kidding aside, it is a lot of work, and you have two options: 1) learn these things yourself 2) pay someone else to do them for you.
I'm a fan of #1, as they are valuable skill sets that let you be on the receiving end of option #2.
I'm not a fan of the 'devops' term, generally.
There's tons of value in doing things yourself
Caddy has built-in support for Let’s Encrypt.
I use the dns module which required a little bit of extra work to enable because it’s not included by default but other than that it’s very simple like I said.
Here is the config file for one of my sites:
www.crusaders.pw {
root /var/www/pw.crusaders.www/
expires {
match .htm$ 4h
match /assets/.* 1y
}
tls {
dns cloudflare
}
}
crusaders.pw {
redir https://www.crusaders.pw{uri}
tls {
dns cloudflare
}
}
Then just stick the config file in a git repo.Until you write your first blog post or get a single comment. Then you need backups like everyone else who runs their own shit.
This is usually the most important question to ask about a tool for a project.
However, it is reasonable for the answer to be "because I"ve heard that this tool is useful, and I want to better understand how it is shaped and what things are hard/easy to do with it"
I believe this is referred to as "resume driven development".
I backup everything daily to my Synology at home.
I think that Docker is a great time saver for those who want just to play with a new piece of software, and don't have the time to learn all the details of some arcane install procedure.
That's true, but if you do that in production you're running untrusted code that could do pretty much anything.
If you don't have your own Docker registry full of containers you either made yourself or have audited yourself, you might as well let anyone in the world run their code on your servers.
And if you do have your own registry, it's a lot of work and it involves chasing down libraries and working with arcane install procedures. You can't really trust the public base images unless you fork them and audit them yourself, or just create your own.
At some point you need to take responsibility for your own stack. Docker fine for messing around on your laptop but the real work starts when you need to get past that.