Raspberry Pi as a local server for self hosting applications
cri.dev
cri.dev
There are lots of great tools that solve some of these problems. I have yet to find one that solves all of them.
I think we need something like Namecheap + CloudFlare + ngrok, designed and marketed for self-hosters and federators. You simply register a domain and run a client tool on each of your machines that talks to a central server which tunnels HTTPS connections securely to the clients.
Mapping X subdomain to Y port on Z machine should take a couple clicks from a web interface.
You'll need don't need any of that with Onion Services. Tor does not only anonymize, but offers easily configurable services with NAT punching, an .onion Domain and e2e crypto for free. And setting them up is easy enough https://community.torproject.org/onion-services/setup/
You'll just need tor or a tor browser to access those services, but that shouldn't be a problem for many self-hosting setups
Unless of course, you are running a node.
And for all we know, the NSA snoops traffic at all major internet exchanges, so tor exit nodes might get extra attention, but so do e.g. people who's search history suggests they might be sysadmins (if i remember reports on xkeyscore selector correctly)
It sets up WireGuard (also feat. NAT hole punching) in a mesh between your devices. You can static route things to it using standard firewalling/iptables/etc if you feel the need too.
It's basically having a LAN but you're on the LAN even when you're not at home.
Edit: Hahaha. I discovered Tailscale myself through this thread, left the tab open..
PageKite (https://www.pagekite.net) is what it sounds like you're looking for. It'll set you up with a url, SSL, and a tunnel in about 30 seconds. Highly configurable for your own domain if you'd like, multiple ports etc.
Plex does the plumbing for you, I think NextCloud might too.
Doing DNS just seems like another thing to setup which is just fine. Pay namecheap, then pay a big boy DNS provider (I like dnsmadeeasy) then register some domains.
I don't really want a solves everything tool because I don't see a way for it not to be really opinionated and hide everything behind its own abstraction which isn't really any better than the interface it is hiding. Maybe a series of how-to whitepaper kinds of thing to build up the requisite knowledge to figure these things out.
I'm not a fan of the old school configuration hell where you have to spend hours/days/weeks trying to figure out the correct set of software and config options to do something right, but I'm equally not a fan of completely canned solutions that hide everything in favor of a single button to push. I'm not a technician, I don't need to have everything done for me, but I do appreciate tools where right configuration interface is provided. That is, sane defaults, well documented options, meaningful errors and sanity checking, and options given in the right way.
Docker allowed me to be far more competent on a Linux box than my skill set should have permitted at the time. I no longer needed to know how an application ran, just that it did. Provide some persistent storage and you’ll probably never have to configure that app again. Amazing.
The problem is package managers are bad (well, apt is bad, rpm is pretty ok, freebsd ports are pretty good, there are many others) and package maintainers are bad, it always seems like the job they give the intern to figure out instead of making it a cornerstone of usability.
Seriously, spend a day setting up things running on freebsd with the packaging you have and it will be a breath of fresh air. Nearly everything you can think of all put together in packages in one place, and most of them start working in an expected way with zero configuration fiddling, install and start.
If package management were better, docker might not have existed at all, people keep confusing it with decent package management.
And, of course, it can't reach out to your phone because it's also behind CGNAT. So, you need a VPS to act as a bridge between your phone and the device, which would connect to the VPS on boot and route traffic through a tunnel.
A VPS with a VPN works but there's alternatives. Some online services provide free port forwards/port forwards for a price (ngrok style) or if push comes to shove and you only need access yourself, you can probably host your services on a Tor hidden service and bookmark it.
I don't think I've seen that many ISPs do CGNAT though. Even mobile carriers often expose some ports to the outside world for IoT crap with a SIM card. Maybe CGNAT is more prevalent in other countries but that doesn't mean other people can make use of these guides.
On mobile networks, you are assigned a CGNAT IP address per cell base station per device, and they are then all mixed into a few public IPs. There are no ports open, and they cannot be opened, becase it is not possible to assign ports to a mobile device and have the user know which ports to use.
Because hundreds or more users share a single IP address, you'd have to randomly assign them ports and keep track of devices entering and leaving the service area to delete the port mappings, which is not economical.
Ironically, one mobile carrier - Telenor, has a "feature" where on 3G only with a certain APN they assign you a public IPv4 address to your mobile broadband interface. The only catch is that it is reachable from Telenor's network only, except on ports >10000.
It’s pretty easy and free to get IPv6 from HE’s TunnelBroker.
But this is not something new of course, everybody will tell you to either use good uSD cards or put the os somewhere else, like an external hdd or so.
microSD cards (and all flash storage) has a limited number of writes. If you let your rpi write logs, you will soon run out of writable space and if you are lucky you end up with a card that is read only. If unlucky it just stops working all toghether.
With the PI4 you probably can even get better performance from using a USB storage device as it has USB 3.0 Ports.
It doesn't have the address exhaustion that caused providers to implement CGNAT, and dynamic IPv4 addresses.
No need for VPS management, DynDNS, port forwarding, hold punching. You still need public DNS, but you can use public DNS as your internal zone as well (no need for split DNS). You also still need PKI, so maybe setup a reverse proxy for SSL termination with a wildcard certificate.
RFC3053[0] seems to indicate this can be a problem as well:
> 3. Known limitations
This mechanism may not work if the user is using private IPv4
addresses behind a NAT box.
Are you saying it works even behind a NAT?EDIT: According to HE's own FAQ[1]:
> If you are using a NAT (Network Address Translation) appliance, please make sure it allows and forwards IP protocol 41.
That doesn't sound like something most ISPs are likely to support. Not sure about home routers but if it has to be configured manually we're back to square one.
I didn't even realize this was possible: https://tailscale.com/blog/how-nat-traversal-works/
I had seen some of the people working there comment on twitter, but I don't think those blog posts were written when I last looked them up and I didn't understand what they were actually doing.
This looks like the answer for most people if you don't need to give public access to the stuff you're hosting.
If you do though, I'm still not sure what the thing to do is. If I wanted to host my blog from home instead of via github pages or digital ocean, what's the right way to do that? Is there a reason nobody does this?
Nowadays I just pay for a $5 VPS somewhere -- my uptime is significantly better this way!
I am setting up a self-hosted lab and looking at (securely) setting up remote access. Was leaning towards OpenVPN as pfSense supported it, but have been considering a locked down VPS remote proxy too (at least for some services) and happy to hear thoughts.
Does Tailscale offer domain registration and TLS certs?
Also, is there any way to allow public access to certain ports on certain machines, ie if you wanted to run your personal blog on your RPi?
You mentioned accessing your own devices from anywhere, and that's what I use Tailscale for. It was a dream to set up, and for my own services, I don't need TLS or custom domains, really. I have a few shortcuts on my phone that work everywhere, Tailscale IPs are static.
> Also, is there any way to allow public access to certain ports on certain machines, ie if you wanted to run your personal blog on your RPi?
This is sorta outside the scope of what Tailscale aims to solve, but one of the cool things you could do is just run a proxy somewhere publicly accessible and route requests to your RPi.
I think maybe you're misunderstanding what my goal is. If I have a local webserver running on my laptop on port 8080, I want to expose that via HTTPS on a public domain. The server that terminates the HTTPS connection needs root to run on port 443, but my laptop doesn't need root to start the upstream webserver on 8080, and it shouldn't need root to tunnel it to the public server either.
I think somebody even compiled Tailscale to run natively on my Synology NAS.
It’s always run perfectly fine for me and my needs, and I even tested having shared video calling in NextCloud and it continued to work great.
I’m not sure your configuration, but it might be worth trying on a Pi4?
I do treat it like I would a Dropbox. I store photos I want to save, documents I want to save, etc. I was using it for recording trips for a brief bit, as well.
I’ve used it to share pictures with friends from our hikes, and I’m on a very fast internet connection.
My usage loads might be sufficiently low to not be a problem. I’m not constantly streaming from it like LTT does their NAS. For major software projects, I might use it as a remote git repo.
I probably have a high speed SD card.
There are times when it’s slow, but not too often. I forget what I’ve done to resolve that.
Also, running the NextCloud app on my computer has never been slow and that’s my normal use case for file management on it.
[1]: https://www.raspberrypi.org/forums/viewtopic.php?t=245931
The 4 might have a better change with gigabit internet and faster usb, but I was still using a fast samsung fit drive, but not fast enough.
To be honest though - the intel box was modest, but still 4x the price. Additionally it's hard to beat a pi for installation - just insert the sd card. (there is always configuration)
There's a full-automatic mail server program, maininabox, that tries to be this instant "just make it work" system. The result of the project is that the host OS was severely outdated for years because upgrading configuration automatically is difficult and because the system manages DNS for you, adding a new subdomein to your server is more of a challenge than it should be.
Similarly, automatic service install and management tools like Plesk, cPanel, ISPconfig have been around forever but they always provide some limitation. I think Sandatorm.IO is a quite recent tool of this sort that runs Docker so you have a bit more control.
All of these still require occasional maintenance though. If you can't figure out how to point a DNS name and a wildcard to your IP, then I'm not sure if you should be exposing services on the internet like that. If you don't update for a while your nice, powerful server Raspberry Pi might suddenly be DDOS'ing random websites without you even knowing about it, and all you can do to prevent that is to keep your (limited) software stack updated.
All attempts to make this easy for the general public have so far shown that people don't like to press the update button; even rebooting Windows is a risk some people just aren't willing to take, which is why Microsoft had to force reboots in Windows 10. With that kind of risk out there, freely connecting whatever to the web and forgetting about it, I'm glad there's some technical requirements before you can host something.
* Argo smart routing is 5 USD/mo + 0.1 USD/GB. The 5/mo is fine, but the data charges could add up quickly for something like Plex.
* CloudFlare doesn't sell domains.
They do have a domain registrar intermediary [1] announced two years ago [2]. It's in cooperation with dount.domains and has competetive pricing. It could be counted as they do sell domains.
Not affiliated with them in any way.
[1]: https://www.cloudflare.com/products/registrar/ [2]: https://blog.cloudflare.com/cloudflare-registrar/
If you ever wanted to learn k8s without spending $80\month on a cluster, best way to learn it!
Ideally, you don't need to learn Kubernetes any more than you need to learn Linux in that example - our Repo Builder will do it's best to guess how to host your app on Kubernetes - and ideally the UI makes the rest feel like any other cloud platform. The benefit of not being locked in, and of learning open source tech instead of walled-gardens, is hard to express!
route53 can work like that, it also has a cli version. (But you can't get the domain there).
There's Amazon Domains now.
Additionally, https://github.com/crazy-max/ddns-route53 works well as a dynamic DNS configurator for Route 53.
For most home users, a Docker-supporting server is the best option.
Traefik has ACME and labels-based configuration for Docker hosts. It is a good choice for multiplexing HTTPS services by subdomain names.
In my opinion the biggest limitation is that there is no universal API for network routing appliances, whether it is your $30 home combo WiFi/router or your $20,000 Cisco device.
An access-key-authorized version of UPnP would be sufficient for the vast majority of users. Or even iptables commands over public key authenticated SSH.
But giant corporations - Google, Microsoft, Apple, Amazon, Facebook - they are in the cloud business, Microsoft doesn't ship a home server technology really anymore.
The most popular home server software, like Plex, is really purposefully disruptive to giant software and media companies. By contrast you're going to have a bad time running your own Dropbox competitor from home, because that sort of technology is engineered around cloud computing.
This is already the case. Routers have mostly easy webinterfaces nowadays en the same goes for DNS options at any domainname provider. What people need is a bit of knowledge. It takes me a few mouse clicks in a webinterface to do this because I know what I am doing. Yeah you could dumb down anything to a single button but I don't think we should want that.
I'm using this WebRTC method for 3D printers at https://tegapp.io
- NodeJS DataChannels: https://github.com/node-webrtc/node-webrtc
- Rust DataChannels: https://github.com/lerouxrgd/datachannel-rs
There are still many features to implement, but we are working towards "easy self-hosting at home", and looking for early adopters.
Why limit it to specific software, rather than simply port mapping?
KubeSail feels like a more accessible k8s+docker apps to me. I am not sure what security model KubeSail is assuming for the operating systems it is running on (or does it assume the OS is out of the scope?). Also KubeSail seems to target mostly developers/hackers.
Problems with the "easy" one click ones is that they tend to not be very secure. If they are supposed to be public access. Plex uses their cloud to secure the access and Synology to
Bought a namecheap registry for a small nfp.
Been swamped with how-to’s and learning things just to learn what to search for...
I could use something else that does it all...
But I want a level of authority none of those offer.. without the technical insight of “is this everything/enough”.
EDIT: Oh and if you don't mind managing your DNS records manually, including dynamic DNS.
A workaround that can save you some headaches here is to only boot from the SD card (which means you're effectively only ever reading from the card), and then mount a filesystem on an external SSD drive. There are a couple of good guides here [1] [2].
[1]: https://www.stewright.me/2019/10/run-raspbian-from-a-usb-or-...
[2]: https://www.pragmaticlinux.com/2020/08/move-the-raspberry-pi...
I generally use a decent USB stick nowadays. RPi 4 from about a month or so ago onwards will do this out of the box. You can also put a second USB stick in and clone the thing every now and then.
You can PXE boot them as well (citation needed) and that brings nfs and iSCSI to bear. That's my long term plan for fleets of them.
For the semi casual user, I recommend the dual USB stick combo. Quite easy to set up and you can always whip out the backup and test it on another device.
Are you saying you don't need an SD card at all and it will just boot off USB?
Pi really shines when you are interacting with hardware sensors, or need ARM.
I also like it because they force me to use Ansible and actually make my installs repeatable. On my actual server, practically everything is some snowflake crap I did at 3am that I couldn't repeat if I had to.
"Fleet" is a bit of an excessive term but I have four RPis at home, mainly for TV frontends for MythTV. There are rather more in the office.
The above is just a sample and not the whole story 8)
[1] https://www.samsung.com/us/computing/memory-storage/memory-c...
Anyways, I assume that the following is what you are referring to: https://www.raspberrypi.org/documentation/hardware/raspberry...
In that case, the following from the linked page might be worth making note of:
> To enable USB host boot mode, the Raspberry Pi needs to be booted from an SD card with a special option to set the USB host boot mode bit in the one-time programmable (OTP) memory. Once this bit has been set, the SD card is no longer required. Note that any change you make to the OTP is permanent and cannot be undone.
Not that it matters much to me but still something worth being aware of if you later try to repurpose your RPi for something else I think.
> Raspberry Pi 2B v1.2, 3A+, 3B, Compute Module 3
Further down,
>Raspberry Pi 3B+, Compute Module 3+
> The Raspberry Pi 3B+ and Compute Module 3+ support USB mass storage boot out of the box. The steps specific to previous versions of Raspberry Pi do not have to be executed.
Then the last one,
> Raspberry Pi 4
>The Raspberry Pi 4 currently requires non-default firmware to enable USB mass storage boot: see the USB mass storage boot section of the Pi 4 Bootloader Configuration page for more information.
But overall, it's possible in some way with all these versions,
>Available on Raspberry Pi 2B v1.2, 3A+, 3B, 3B+, and 4B only.
I have wasted alot of time and lost a not insignificant amount of external data.
I am about to buy a FreeNAS mini tower.
FreeNAS is a good choice. Should last you for years, baring any kind of weird/unusual hardware problems (which aren't expected anyway). :)
Booting to USB protects the install better, allows easier access or setup on a PC, and I have more of them around to set up random OS or systems to test. I have several pis around and each that can boots to USB including the pihole systems at my parents place and grandma's apartment.
Plus, the SD copier tool in Raspbian works with USB drives (and VHDs) so I set up the pihole for my grandma, cloned the usb drive, then sent both drives to her with the pi and called to walk her through plugging things in then used my existing remote tool on her laptop to finish set up. Now she has a backup USB drive that may need updates but is ready to go if the existing USB fails with pihole ready and everything. Plus once I update the backup drive I can clone it to the corrupt USB and she can store that as backup.
I know many people have hard lines for supporting friends/family. I've taken it in stride with super useful setups for relatives (pihole and a remoting tool if I set up their laptop/desktop) and beer or similar cost for friends. One recently spilled warm garlic sauce in their laptop so I pulled it apart while they scrubbed and wiped and some local beer is cheaper than a new laptop any day.
Just stumbled upon this today by coincidence, will definitely follow the suggestion, cheers
That seems like most of the value to me, hosting some service you can access from anywhere without having to use Digital Ocean.
It seems like most residential ISPs don't provide a static IP and some block port 80? I think forcing ISPs to allow home users to serve traffic via some standard method would go a long way to enabling a more decentralized web.
I know Zero Tier, and Tailscale exist - but I don't really understand how they work (and I think they require intermediate server access anyway so might as well use Digital Ocean?).
I'd like a future where you could sell users a raspberry pi running a service they can just plug into their home switch and access it securely from anywhere.
Interesting.
The only place you get stuck and need an intermediary vps is if you are behind CGNAT. I came across this recently that helps set all that up. https://github.com/erikespinoza/v4raider
Wireguard, listening on the public IP with port forwarding, and using a dynamic dns client to ensure I can always connect even if the public IP changes.
> It seems like most residential ISPs don't provide a static IP and some block port 80?
Not the case here in my experience (Spain), but if you're fine being the only one with access you only need to forward the VPN port.
> I know Zero Tier, and Tailscale exist - but I don't really understand how they work
I only used ZeroTier a bit, but IIRC it was something like:
1) Create a new network in the ZeroTier One website 2) Download the ZeroTier client on your machine(s) 3) Enter the network ID 4) (optionally) authorize the device on the web UI 5) Now the device can connect to other ZeroTier peers on the network you created!
(So yeah, at least the "easy" way involves using their server, no need to selfhost it). Also this option should work without port forwarding.
No idea about ZeroTier, but you should be able to use WireGuard without root access using the userspace implementation in Go[0] (that's the one used in non-rooted Android phones, Windows, and maybe the BSDs)
These central servers basically exchange the external IPs of each machine on the virtual network. The nodes on the virtual network then try their best to establish peer-to-peer connections using those external IPs.
I use it all the time with a number of colleagues working from home and it works great! We can all join a virtual LAN and see each others machines behind our home broadband routers.
ZeroTier runs fine on Raspberry Pi. I use it to link machines at home with machines at work, on AWS, Azure, etc.
In terms of accessing local services, I'm using StrongSwan on a VM with the relevant ports forwarded from my router. Ideally, the router would run StrongSwan, but until I switch to pfSense I'm living with this setup.
iOS and MacOS devices get a .mobileconfig profile which automatically connects when needed and disconnects when the device returns to my home WiFi network. My Linux travel laptop can also connect, but I haven't figured out how to make this happen automatically yet.
Why can I not sign up with email?
Why is there no way to contact the creators to ask these questions?
You definitely shouldn't expose most of these things directly to the net, they're not always bulletproofed as much as one would like.
Oh, I also set up a dynamic DNS service on said router, even though my IP address seldom changes, Murphy's law says the most important time for me to be able to tunnel home would be after an outage or something that reassigns the IP.
For hosting an email server a static IP is all but required, so I got the free tier VM.Standard.E2.1.Micro VPS at Oracle Cloud. It has a static IP and I forward stuff to my rpi3 with dyndns. All you need for this is a credit card.
some routers block rfc1918 addresses from dns lookups, but you can turn that off, or put your virtual lan in a different range.
Then you can have sql01.example.network point to 100.13.14.15
My ISP doesn't seem to block any ports or anything like that, nor have I ever had any such trouble in Norway (been through a few ISP's here)
As far as overheating, there are several passive cooling cases that handle the heat just fine. ETA Prime is one place to look for videos with tests.
No doubt you get more power and flexibility from a NUC, but Pis are pretty great for what they are.
I tend to think of Pis in terms of single function appliances. They're obviously capable of more but they're so cheap you can just throw one at a single problem and forget about it.
I needed to test out an Onvif setup, I was able to flash a Pi Zero W and have a functional Onvif camera in 20 minutes.
We got some windows blinds and I noticed they used Z-Wave remotes so I pulled out a Pi and setup an HA server running them on schedules with-in half an hour.
Such a bright future in home-hosting - really looking forward to seeing the movement grow! The https://www.linuxserver.io/ community is pretty great re: home-hosting apps as well.
I originally had a Cluster Hat (https://clusterhat.com/) which piggybacked four Pi-0's on a Pi 3. Even cut out a nice acrylic case, too (https://climbers.net/sbc/clusterhat-review-raspberry-pi-zero...). It worked fine, and I even had Hadoop running on it for a while. The biggest issue was the ARM7 of the host (pi3) vs the ARM6 of the Zero's. This caused a lot of problems with deployments, essentially eliminating the redundancy you get from orchestration systems.
Gotta definitely try this, thanks
https://www.jeffgeerling.com/blog/2019/raspberry-pi-microsd-...
Obviously a RPi is a way cheaper way to get a lot of the same work done though :)
It has PiHole, Nextcloud, my humble little Netflix clone, and a few other things. If you use ffmpeg a lot, you ought to have more power than the RPi offers. I often SSH into it to use it as a SOCKS proxy in other countries.
Before I switched to Ubiquiti I ran pfsense on a VM on my old 410s for many years, among other virtual machines for home lab use.
how does that compare to RPI?
Thanks to cloud-init (Old version though) you can even pre-configure the boot image with your SSH key etc. which allows you to automate your initial install.
https://blog.hypriot.com/downloads/
https://cloudinit.readthedocs.io/en/0.7.9/topics/capabilitie...
sounds like a super smooth dev and deploy experience
Turns out that modern electronic devices are expensive. If you are not charged up-front, there's a good chance that you are being charged in some other way.
I went a saner route, and used dnsmasq and a blocklist[1] updated nightly via cron. Dnsmasq in turn queries Stubby that talks to uncensoreddns.org via DNS-over-TLS. Boom, DoT on my entire LAN.
https://computers.woot.com/offers/lenovo-thinkcentre-m73-240...
Also, the Pi 4 eliminates the USB2 bottleneck the old Pis have, and has a couple of USB3 ports.
[1] Be sure to boot with arm_64bit=1 in config.txt or you will get no work units.
You can safely expose your self-hosted websites to the internet and without the hassle of needing to have a VPN connection first.
I've done this with a Pi and Dyndns. It's pretty easy to setup but not as good (for me) as a DO vps because my home ISP limits data heading out. I would have to purchase a business plan to fix that and it still wouldn't be better or cheaper than what DO and others can provide.
A Pi can be used for development on your home network and it excels at that. And the older RPis can run [1]CouchDB and be configured to "Live Sync" with a CouchDB running on a commercial VPS. That too is a pretty easy to setup and it provides some pretty nice options. For example, you can make your app use the Cloud based CouchDB while you're out and about and it will sync your data with your local CouchDB. Then when you get home you can turn off the cloud access and even delete your data on the cloud DB.
1. The latest version of CoudhDB (v3.0+) doesn't run on the new ARM based Pi 4.
So I might expect it to be on par with that old of a macbook but not beat it by nearly 2x, particularly if the macbook is being accelerated. (despite having 2x the core count) Which makes me think the MBP may be suffering from some serious thermal throttling, which wouldn't be uncommon on machines of that vintage.
I also assume the call line is:
https://github.com/christian-fei/raspberry-pi-time-lapse/blo...
which is noticeably missing the -hwaccel switch, which means its probably not using the GPU on the mac..
Well, you do get about 96 Gflops. That was pretty respectable hmm... 12+ years ago.
If I for example wanted to just access my media library through firestick and windows with a kinda neat interface without paying anybody or making an account on a third party website, is there a solution?
I suppose I could just use VLC, which is fantastic software that isn't particularly beautiful and get used to it, but I'd like a somewhat more "netflix-style" interface for navigating my content within a single rpi server on my network.
Setup your media (local or remote) library, and the scraper will enrich it with posters, synopsis, actors, etc.
[1] https://kodi.tv/
I've had success with Kodi in the past with my laptop but I've also had big performance issues on the firestick. To be fair, it's been a couple years since I tried that so I'll see if the newer versions perform better.
(For context, we get a lot of requests to port Cloudron to ARM/RPI but I am still not sure if these are just hobbyists/tinkerers or something people use everyday.)
n8n is not open source, despite being source available. The author goes to pretty great lengths to avoid confronting this fact.
https://wiki.debian.org/FreedomBox/Hardware#Also_Working_Har...
I use it for CI/CD on projects, but also for automating other tasks -- You can use Jenkins to wrap any arbitrary script with more higher-level logic and extensibility than a cron job.
For example, I use Jenkins to automate multiplatform builds for some side projects, to periodically ingest data into a database, perform cleanup jobs, etc.
Just set up a Tor proxy that I can connect to with one command from my PC, by connecting to the PI via SOCKs proxy, good times
Just last week I bought a 500gb SSD and usb adapter for about $75. My Pi 2 powers it without issue. The only problem I see is that the SSD can get fairly warm, so keeping it in my closed center console probably isn't a good idea.
Benefits:
- way faster
- always on (presumably battery backed)
- you're not responsible for disk or hw failures
- better internet (faster, redundant connections)
- cheaper ($60/year vs $100 upfront)
- not fighting architecture differences
- comes with a public v4 address
- usually comes with a v6 address too
Downsides:
- data isn't under your control and is subject to military espionage
- your internet connection to move larger files to/from the remote device may not be great