Why My Blog Is Closed-Source
joshwcomeau.com
joshwcomeau.com
If he wanted to hide his designs so much he could just put a login page for folks he wants to vet. Any page you send to the client obfuscated or not is sent to the client, period.
The rate-limiting he wanted on some counter is the weirdest thing, just have users login if you are so bothered about server less bills for something so trivial.
* The unpublished posts would require a different workflow; you could easily keep a private repo and a public repo, and publish by pushing from private to public.
* I don't really see a problem with copycats, personally. I personally feel like theme/design is just a minor style thing on top of the content and not even something that you "take credit for". Like, if someone wants to copy everything but the content of my blog, more power to them.
* The security angle is basically adding obscurity, which is a reasonable additional layer, however thin.
Yes it does. I know you can never criticize someone else's infra nowadays without coming across as "I could clone StackOverflow and get it to run on a Raspberry Pi over a weekend," I have no idea what or how much stuff his backend is doing, and I know serverless is an added and often worthwhile expense....but man, that's way more than I'd expect.
I'm not sure how many hits per day that works out as, but currently I have a server that is 5 euros per month handling 20k hits per day (static and dynamic content on an old dedicated C1 Scaleway). Another server I run for a gaming community costs $1 per month.
> I have no idea what or how much stuff his backend is doing, and I know serverless is an added and often worthwhile expense
I keep looking at 'serverless' (+) - but it just seems like a way to sell me less for more. The benefit I get currently from a cloud solution is location (spin up an instance close to where the traffic is coming from), maintenance (I move around a lot) and network (dedicated high speed internet that cannot be easily DDoS'd).
(+) When I first heard about serverless, I really hoped it was a decentralized content hosting network - a bit like how something like PeerTube can benefit from having multiple users at a time. A person can dream!
He uses ConvertKit. It's amazing the total is only $130, given the popularity of his site.
From 3001 to 5k subs is $79/month on their basic plan and $111/month for the pro plan. No idea about larger lists, but they're not cheap.
Really depends if an organization uses its own blacklist besides the major public ones.
And, if you get an IP banned on a major public list, you can easily request removal - takes less than a half hour.
Just don't use AWS as the host.
I am so sick of everyone saying it was so hard, when we have solutions like http://mailinabox.email or http://mailcow.email. Then it looks like a mailing list isn't too hard: https://github.com/maxking/docker-mailman
After intial setup mailing is so low maintenance now-a-days.
Here is one of the maintenance pages of one of the projects you linked: https://mailinabox.email/maintenance.html
I am not sure what sort of Lambda function you are referring to, but an AWS lambda is dead simple compared to that maintenance page.
Also, time. When there's a problem, it's still on you to fix things, instead of having customer support.
You and the author seems to value their own time in different ways, and have different expectations on features a newsletter needs, and how much involvement with the service you are willing to have.
I do like it, though, even the silly heart feature which I would have expected to hate.
My entire working folder with markdown posts, drafts, templates etc is a private git repo. The output (the static HTML, CSS, images etc) is a public repo.
I have a tiny shell script to commit, push and publish the site, and it works just the way I want it. His other points are understandable. I personally don't take my blog that seriously, it's just a pet project.
I'm not a web-text-purist, but audio in a document is where I draw the line, that annoyed me.
A tip from over ten years of FOSS : never try to track your FOSS code, nothing good can possibly come of it
http://bettermotherfuckingwebsite.com/
I really don't understand why something like a blog needs to be much more than this to be honest.
( As a comparison)
Years ago I told one of my coworkers that I brought in my bike to the repair shop to replace the tire for €15. "€15? You can just do that yourself?" Sure, but I'd spend 30 minutes mucking about and and getting my hands dirty. It's not like I got a stash of money to burn, but I'd rather just pay the €15.
We had more troubles with work with "the cloud".
Setting it up was just pressing publish in VS + git and 1 time the domain+site ( 5 minutes in total ). So I spend less time on it.
Everyone seems to forget that every deployment needs to be configured somewhere. If not by you, someone else.
The server is windows server with IIS. Nothing special, you can get it for the price of an 1 Shared App Service in Azure ( 10 € / m = 1 Windows Server) vs 8€ / month ( 1 Shared App Service).
I didn't had to do maintenance in the last year. But I did create a custom statuspage. But it's used mostly to deliver updates of clients when I deploy ( it creates a RSS entry when I deploy, which clients can receive).
Clients are notified 100% of the time with updates from the developer as soon as it happens, if they want it :)
I suppose with your 20 years of experience ( Github exists since 2008 as a reference), you can give me some actual examples that the cloud improves on workload?
Eg. I have a small member management saas that I haven't touched in the 6 years that it's running. I just realized that it's probably hosted on my test server ( my first VPS) and if it wasn't used, I wouldn't have been able to send the yearly invoice :)
The dogma is in thinking that the cloud makes everything simpler. It isn't. It makes difficult things more simple, but in a lot of cases, you don't need them in the first place.
> The dogma is in thinking that the cloud makes everything simpler.
I never said anything of the sort. Everything comes with trade-offs. I host my product on two Alpine Linux VPSs. But I also spent time setting all of that up and need to spend time maintaining it. For personal projects, cloud tools like FastMail tend to be the better choice in most cases.
I was talking about client projects. Hosting email isn't a client project and is something I wouldn't selfhost either.
When I mean creating projects in the cloud, I'm talking about using the big 3 Google, Microsoft and Amazon cloud. I even explicitly mentioned azure...
Netlify is build on top of AWS and for them, it's useful for actual scaling on the "edge". But most sites on netlify don't need their edge capabilities.
And cloudflare is one self hosting it on more edge locations ( i think they could even join the big 3 soon)
And still, some customers had issues 21 days ago with netlify DNS. So those clients spend time on that too and didn't knew what was happening at first
https://news.ycombinator.com/item?id=26581027
Additionally, here are some edge cases you can run into for DNS:
https://answers.netlify.com/t/support-guide-dns-quick-start-...
But i guess those issues don't count as "maintenance/work" :)
I too prefer for my blog to be closed-source, for many of the same reasons.
Mine is decidedly less sexy, it's just Laravel + Markdown, but I did write about it recently: https://aaronfrancis.com/2021/blogging-with-markdown-in-lara...
> SInce it's closed-source, none of that matters to me. But if it was open, folks would want to grab it to use in their own projects. I'd feel a certain responsibility to make sure that it works well, or at least to make sure that its shortcomings are well-documented. And I don't want that responsibility right now.
I see this argument over and over. I see it in academia as an excuse not to share code and data. "I haven't cleaned it", "it might not work for you". *I* will decide if it fits *my needs*, and if it doesn't I don't see how it's your fault. Code is better than no code, I always have the option of not using it.
The context for this thread is whether this is an acceptable reason for keeping source closed. It seems from context that you don't believe this is an acceptable reason. You also say that if I can't ignore people that I should turn off my internet, which makes me think that you believe this is an acceptable response.
Thus, I believe that you believe that turning off the internet is a reasonable response and closing my source isn't.
My comment was meant to be hyperbole since I think if you're unable to ignore people online you should really just turn off your internet because it's really easy to ignore people online. I did not mean that you must make your code open source. I don't really care either way about that.
Even with the small amount of open source software I've maintained I've gotten all kinds of angry emails and completely useless "bug reports" with no information. It gets exhausting after a while, and I agree that it's hard to just say "I don't care at all" when it happens. At minimum it's a bad look for you professionally if you never actually help maintain your open source software.
Having aspirations about your project becoming a victim of its own success is good. Overselling your own success before it’s caused you a single issue is probably not good.
Other situations like research, typically need the same materials to do verification of that work.
Of course the problem of research is slightly different, since you have a claim, are trying to be "peer reviewed", and possibly were funded by public money.
Take a look at the issues of any popular Github project to see this phenomenon exacerbated.
Coincidentally I stumbled upon an example today while randomly browsing Github projects. A project with 9k stars and someone opens an issue basically saying: "commands do not work": https://github.com/walkor/Workerman/issues/611
I don't mean to do finger pointing at this person. It's a common behaviour.
For maintainers it's exhausting to pursue each and every issue, asking for context. And if you don't keep a tight leash on them or use a bot they just pile up to hundreds of issues.
It was an amazing amount of ugly drama to try to talk to others with my condition about what I do and what I think about why it probably works. And then people would take very conservative bits of advice that were the most well established and screw them up to an amazing degree.
One example: Coconut oil is a very well established beneficial supplement for my condition that is medically recommended and this is common knowledge for the CF community. It also tends to cause diarrhea.
So "on my advice", someone began giving their toddler like a freaking tablespoon of coconut oil per day -- which is insane amounts to give -- and the result was very extreme amounts of diarrhea that couldn't be contained by a diaper and resulted in the floor needing to be mopped (like every single day until she finally said something to me and I was like "That's waaaay too much coconut oil to give").
So, ultimately, I left all the lists and I still write about what I do for my health, but I've worked hard at figuring out how to talk about things to a lay audience knowing that some of them can manage to do amazingly stupid and harmful things with the most conservative suggestions. And I mostly don't have an audience for that kind of writing and I'm okay with that. Go have your dumpster fire elsewhere and don't try to pin the blame on me, thanks.
Code no doubt has some people like that. And there's a crazy amount of built in assumptions that the original author will know but may not know he "needs" to document and spell out explicitly so some random internet stranger doesn't create some dumpster fire and claim it's someone else's fault because "no one told me...!"
And no amount of "use at your own risk" type language is enough to protect you from crazies who want something for free, aren't competent enough to effectively deploy it and now think that freebie owes them like they paid good money and it came with a warranty.
If you want to make absolutely sure the "crazies" don't get any bad ideas from you, the only way is to not publish anything at all.
Yes, any time you publish anything at all, you risk having someone misuse it. But someone who replicates a thing and messes it up where you didn't provide the source code is less likely to act like "you did this to me, you evil monster, you." More importantly, the rest of the world is less likely to hold you responsible.
Publishing A and publishing B don't come with equal risks. He is choosing to mitigate risks for reasons that make sense to him in areas that matter to him and explaining it on his blog.
You can feel however you feel about that, but he has a right to make those distinctions and choices whether you like it or not.
Irony, incarnate.
My personal experience is that my paid customers have been much friendlier and less demanding than users of things I've put out for free. That's not a problem in and of itself: sometimes demanding users is just what I need to sharpen up myself and what I'm building. Having noticed this, though, I've tried to be more thoughtful about what I put out, in what format, and under what terms.
All that to say: I sympathize with both points of view.
Wouldn't it suffice to just have them in a different, private branch? The public stuff would be in the main branch pushed to the public repo, the private stuff would remain local in the private branch?
Ultimately, a simple "because I don't want to and I don't want people to copy me, thus I'm not making it trivial" would have been enough.
I have toy site that gets around 100k users a month, with background services like a postgres db... and it costs me under $20 to run. I do everything in CloudRun (serverless) with a managed DB. What in the hell is this person doing?
In all seriousness, running a blog that relies on serverless invocations would guarantee I’d do everything I could to avoid anything popular in case I had to pay out of pocket for a huge traffic surge.
Email: $5-$10 FastMail plan, up to 16k emails a day
VM: If you manage to spend $120 here, you've fucked up somehow since you're hosting a static site with a like button.
As another comment pointed out, he uses ConvertKit for the newsletter, which can cost up to $59 per month for up to 1k subscribers[1]. If he has 10k, the cost would be way higher.
I'm at a point in my life where for non-core activities/interests, I'd rather / more easily spend $100 to have a turnkey, than $20 but spend 10 hours :-/
(understanding that the author's reasoning is wildly different of course)
This blog has seen 14,000 views today, but some of the other pages are ~38-40k views
So if you assume ~990KB average page size, 30k views, and he were to post once a day, then that is $78/mo in bandwidth costs assuming 9c/GB. Maybe people tend to click around to the homepage / old articles, or refresh the page a few times?
When you're feeling comfortable, buy a domain and set up LetsEncrypt for SSL. If you've found a limitation in the VM provider, consider moving to a different one. Consider whether a CDN is the right thing for you.