Hetzner now provides IPv6 only dedicated servers
hetzner.com
hetzner.com
I monitor 3 other IPv6 locations, the monitoring server will very randomly throw alerts, and only from Hetzner. Yet, when I opened a ticket, I was told it was the fault of the other providers, despite the mtr traces showing otherwise, and not having issues outside Hetzner.
Hopefully more IPv6 users means that I won't be the only one impacted by those networking issues. I find IPv6 useful for servers that are not public-facing. They are firewalled of course, but it also means I can access them directly from home without hops or VPN (my home having a static IPv6 address).
Stuff like that always makes me wonder how much of it is down to the NSA being hooked straight into DE-CIX [0] via the German BND [1].
[0] https://www.datacenterdynamics.com/en/news/german-court-thro...
"The court said DE-CIX could not cite article 10 of Germany’s Basic Law, which guarantees the privacy of communications, because the company was not directly affected by the BND operations."
I honestly don't understand how an argument like that holds water.
Germany is home to such super weird and reaching legal arguments. If you want another one, check out the BNDs "Space theory" [0]
It has been long established in the datacenter industry that if you build a building in $wierdplace, it is far more beneficial to your bottom line to haul your own traffic to a major exchange point than to pay to have each carrier come to you.
Further, everyone needs to stop worrying about the NSA. Yes they tap cables, no they don't care about what you ate for lunch. Dozens of countries monitor all traffic that crosses their borders, China does the same shit on all China Telecom owned fiber worldwide, other countries probably have fiber tap subs now, corporations will do it too if it makes them money. Encrypt your traffic, deploy TLS on sites you control, and stop trying to frame run of the mill networking decisions or any little issue you have on the internet on the hidden hand of espionage trying to steal your My Little Pony NFTs.
Unless you have a large enough customer base and can pressure carriers into peering with you in weird places. Deutsche Telekom AG in Germany does not peer at DE-CIX because they just don't want to. It's also the reason why YouTube regularly stutters in the evening for DTAG customers.
You are confusing peering (settlement free interconnect) with interconnection points. If you wanted to build a datacenter in Finland and buy transit to reach the greater internet, it will always be cheaper to buy your own fiber to {London,Amsterdam,Frankfurt,etc} than to pay each carrier to extend their network into Finland.
> Deutsche Telekom AG in Germany does not peer at DE-CIX because they just don't want to.
This is false. DTGC is present at DE-CIX and is pushing between 10-20G of traffic. They may not want to peer with _you_, but they are peering across the exchange.
> It's also the reason why YouTube regularly stutters in the evening for DTAG customers.
You don't know that. Most YouTube traffic is served by Google Global Cache servers and doesn't transit the internet or public exchanges. DTAG may not have enough caches or capacity provisioned, but that is a decision they have made about their customers experience. Google will happily give them more cache nodes if they ask.
I was a Telekom customer for a few years and YouTube was just unbearable after 7pm. Maybe they fixed it now or bullied content providers long enough.
You may want to read this Hetzner press release where they address DTAG's peering policy: https://www.hetzner.com/news/03-20-dtag/
It's always been good to me when I was using their European data centers, but that was always a bit of a bummer because of latency. Now that they have a DC in the US, I just can't think of a single good reason to use other cloud providers for smaller deployments. They're pretty much the best bang for your buck you can get anywhere.
Ftfy. :)
Yes, they do, unfortunately. I am still hoping for some regulation / fine to put an end to this.
I've only had them for a few years but I've yet to experience any issues with their great value (e.g 2TB €9.90 /mo) storage box servers. https://www.hetzner.com/storage/storage-box
Only issue I have with them is the latency of their Germany DC's from the US, if they end up offering dedicated servers in a US DC I'll be moving over my existing Hetzner and AWS (non RDS linked) App servers over.
Our first cloud server (supposedly to be a test) is runing since march 2018 We have managed more than 15 dedicated servers since 2012
Never an issue
You're leaving yourself open to having something exploited. Have a look at your ssh logs where "people" are constantly trying to get in.
https://www.whitesourcesoftware.com/resources/blog/top-10-li...
Yes, I check my logs and see the constant stream of breakin attempts. Basic security precautions seem to keep them out.
Another reason though to reboot every so often is for the server to do filesystem checks on the root partition(s).
I am extremely cautious of the sources of UGC I host publicly on my Hetzner machines. In addition to the fact that Germany lacks freedom of speech/publication (thus obligating a German organization like Hetzner to censor content that is legal to publish in most places, but not Germany), I imagine it wouldn't take many legitimate/normal UGC-related issues (e.g. properly-responded-to-by-the-box-customer DMCA takedowns) to make my customer relationship turn negative ROI for them.
I wouldn't, say, run a social media site open to the public on Hetzner, even if I responded to DMCA and other legally-mandated takedowns in single-digit minutes, 24/7/365. I just can't imagine they'd accept the overhead of such a customer.
That said, it's great for hosting big files that CloudFlare's TOS prohibits (video, podcasts, etc), just as long as you're certain nobody at Hetzner's going to get a call over one of your URLs.
Freedom of speech is article 5 of the German constitution.
What you mean is that it differs from the US version.
You can't have "mostly" free expression. It's either abridged or it isn't. Germany censors harmless digital art that the government deems inappropriate for adults to be able to see. It's a classic slippery slope (modern Germans defending their government's censorship and lack of free expression will usually cite Hitler/racist stuff, but that's not all that's banned).
It doesn't really matter what the constitution says, if in practice you don't have those rights. It's sort of like how the 2A in the USA says that the people have the right to keep and bear arms, but I don't suggest attempting to exercise that right in Central Park, because you don't actually have it. Same goes for free expression in Germany.
From https://scholarsbank.uoregon.edu/xmlui/handle/1794/19123 :
> Germany is one of the strictest censors of violence among the world’s video game consumers. Due to its history and a cohesive national opinion, the legislature limits content severely, much more severely than the surrounding European nations. This results in international developers choosing not to market to Germany, creating censored titles specifically for the German market, or finding themselves on a list of banned titles illegal to buy or sell.
[1]: there's also no indication that racist publications were responsible for WW2 (versus, say, Hitler himself), making this censorship-for-censorship's sake. Many other countries do not prohibit racist literature and have not committed a holocaust. So, of course, they banned violent video games too, because those don't cause violence either.
Why leave out the for the maintenance of a well-regulated militia part?
Because the text of 2A does not indicate that the right is contingent upon participation in a militia (and indeed 10 USC 246[1] legally defines the US militia as all able-bodied male citizens of ages 17 to 44 inclusive, as well as all female citizens who are members of the National Guard, even if it did), as 2A actually specifies RKBA as a right of the people (not "people of the militia", just "people").
> In contrast to the NRA’s rigid opposition to gun control in today’s America, the organization fought alongside the government for stricter gun regulations in the 1960s.
https://www.history.com/news/black-panthers-gun-control-nra-...
https://www.schnittberichte.com/svds.php?Page=Indizierungen&...
The US First Amendment version is the only one that is worthy of the name.
De facto and de jure of course being completely different things.
Sure but that ship sailed years ago. Their constitution is also supposed to guarantee a right to a fair trial but obviously the legions of drone victims didn't get one.
The US ranks lower than Germany in the FH and RWB freedom of the press indices [1], which while not quite the same is highly related to freedom of speech.
Moreover, how is DMCA relevant? Copyrighted works are outside the bounds of free speech.
DMCA, and in general the US legal system are extremely relevant to me as a user. If I have a theoretical right to free speech, but in practice any big US media company could kill it then I'm much better off in another country where maybe the theoretical right is 10% less but I can actually practically enjoy that right.
Bad counterexample? CloudFlare did just that, triggering a strangely pro-censorship round of hacktivism in the form of #OpISIS.
https://www.theguardian.com/technology/2015/nov/19/cloudflar...
In the USA, Neonazi publications are allowed, while in Germany they are illegal. Therefore, the US has a freer press than Germany. Freedom House would disagree, and they are simply wrong.
https://www.iamexpat.de/expat-info/german-expat-news/german-...
An appropriate German name is one that is first recognised as a proper name. It cannot be associated with evil (e.g. Satan, Lucifer) or deemed religiously insensitive (e.g. Christus or Jesus). A name cannot be a product, brand, surname or a place name. Finally, German names have to indicate the child’s gender and they are not allowed to cross (one exception is Maria, which can be used as a boy’s second name). Neutral names (e.g. Alex, Kim) must be followed by a second name that indicates the child’s gender.
California like several other states bans the use of diacritical marks on official documents. Last year, the state took up a bill that would have allowed diacritical marks, but it stalled out when a $10m price tag was attached
We don't really like if somebody thinks Hitler was kind of a cool guy and that he should have continued "his work". Besides that you can say lots of things in Germany without getting too much trouble.
It is not an "anachronistic law", it is a new law that came into being very recently.
[0] https://www.spiegel.de/panorama/pimmelgate-hausdurchsuchung-...
[1] https://en.wikipedia.org/wiki/Network_Enforcement_Act#Critic...
https://news.ycombinator.com/item?id=29475379
(tl;dr: Germany censors harmless depictions of gory violence in video games.)
I don't like that fact either but to ignore facts because they don't mesh with my politics is bad.
Germany lacks freedom of expression.
This may be a concern (regulatory risk) for companies who are customers of hosting companies that are subject to German law.
For example, from Wikipedia, "agitation" is not allowed.
Merely disagreeing with a politician can be considered hate speech.
It does not take a lot of effort, either, just using certain words can be sufficient.
Germany now also seems to have the concept of "protected groups" that you can not critizize in any way, which I think is probably new. I am not a lawyer, though.
What they enforce is Nazi shit and pro child abuse publications being banned. Really not objectionable at all. If you must be angry, there are many countries that are significantly worse than this.
- crappy network (advertised 300-500mbps, usually lower)
- crappy cpus ("benchmarked" several providers, hetzner was lower end on cpu-bound loads)
Dedicated ones are baller though, unfortunately no US.
Re: CPU, if you were comparing them with the VMs from "the big 3", you should look under the "Dedicated vCPU" tab: https://www.hetzner.com/de/cloud
Linode/Vultr/DigitalOcean/Hetzner/Terrahost
I can easily imagine cost savings on Hetzner could benefit certain loads, of course. It's always "depends".
How did I come to it? Measuring performance of my node.js service I need to run on it, iperf, speedtest.
From my experience, at Hetzner you are very rarely limited by their network. Usually only by poor peering from transits. Peerings with all the big names are great tho, so no reason to complain for me.
And from what I know from someone near Hetzner, they don't cheap out on peering at all.
10G speedtest to a swedish telco provider I ran just now: https://i.imgur.com/9ARZqOP.png
I think Hetzner's dedicated servers product started from the consumer demand for Counter-Strike servers, maybe it's because Counter-Strike wasn't as popular in the US? Not 100% that's why Hetzner has been succesful with dedicated servers but I don't have another explanation.
Dedicated is starting to make more sense as cloud prices are kinda nuts + tooling is better now, so ‘roll your own cloud’ is becoming more feasible.
It just doesn’t get as much press as the big cloud offerings, and most of them are relatively local players specializing in their region (and associated network/property). OVH has several large DCs selling dedicated hardware for rent here in the US.
The first one I clicked on has options around $50 too: https://www.namecheap.com/hosting/dedicated-servers/our-pric...
https://opennebula.io is worth looking at for that sort of thing (not that it's new). You don't have to do it that way, but its "edge" support for simple provisioning on bare metal providers doesn't include Hetzner; I think it assumes you can get instances on demand. That sort of solution isn't complex or expensive enough for my site, and doubtless others, though. Especially when you just want compute, I can't see the point in the pain (which surprised us) and expense of AWS et al.
I still have Hetzner for a dedicated server in Europe, and it's fine. I've had it for several years now with no issues.
Before getting this job, I noticed that most dedicated servers in America are from smaller companies that re-sell their dedicated servers or colocated servers from companies like my work's or other data centers (who mainly specialize in colocation services instead of selling their own hardware.
I suppose in America, the main people companies target are for simple cheap VPS servers or "cloud scaling" services. You can also make a lot more imo by stuffing as many customers onto 1 server instead of dedicated hardware for each customer. Also a lot less management and support needed. At work 99% of our maintenance and support is for individual dedicated servers. The VPS side of the company requires very little intervention on our end.
Can AWS Spot Instances really beat this? https://www.hetzner.com/dedicated-rootserver/matrix-ax
Networking has been occasionally unstable for me, though. Their vlan stuff being 1400 mtu is also annoying.
does this suggest that their networking gear is also dirt cheap or is this just an artifact of legacy compat and/or not wanting to wory about jumboframes?
I'm a big fan of OVH, they've never let me down.
Sorry, had to poke fun a little bit, obviously there's always a chance of having a bad experience. I've only had to interact with Hetzner support once, and it was positive, we determined that a consumer grade CPU was aggressively going into some sleep mode the Linux kernel wasn't waking up from, and the Hetzner support guy agreed that was the problem and determined it was possible to disable that feature in the BIOS, and went ahead and did that for us.
And of course the fact that that was necessary was on us for running our production on their consumer grade CPUs.
I believe Hetzner and maybe also OVH have a much bigger role to play in the deployments of the future. The big cloud players are overplaying their hands, and it's becoming more and more attractive to run on bare metal as devops tooling improves.
I recall there being discussion about it on HN before and a lot of people being confused as to why anyone needs it though.
No issues so far, but OVH's network seems to be better, especially for people in other continents.
Edit to add:
- I'm using their Germany DCs, not the Finland one (which is cheaper but peering is worse).
- Using a CDN does improve the latency/speed for users outside Europe, but it still influences performance as CDN exit point often connect directly to the origin to fetch uncached content.
- I lost a VPS with OVH's DC fire, but I had backups somewhere else and fixed it quickly. A good thing about the lower prices is that I can have backups on multiple services (also cheap - Backblaze B2, for example) and still save money compared to AWS, Google Cloud, etc.
But besides that, both the cloud and dedicated support are very good. Last 10 - 20 HDDs we needed swapped were swapped in under 30 minutes each, and in some of the more complex issues, they were able to guide our engineer wherever they needed to be quickly. I've dealt with much, much worse hosters at multiples of that price.
They're as on fire as their datacenters
Currently have 10+ dedicated boxes at Hetzner and I'm taking time to write this comment because I like them that much. I only contacted support a few times during my 10+ years there but it was immediate response and to the point. I remember waiting 24h+ for OVH support with my service down (it was 5+ years ago though) and for Hetzner it was always in minutes.
Can you elaborate why do you think they are unskilled?
I failed. They silently suspended my account after i made payment for verification. I tried to register again, they asked for scan of my passport, i sent it, and they suspended my account again. No replies from support regarding that issue too. Funny, because i went through validation process 2 times already (when i rented dedicated servers from them) and now i can't create account to use their cloud offering (and dedicated servers too)
The HDD thing is (was?) definitely an issue with Hetzner. I had the same experience some years ago. Best option was to get hardware raid and SAS disks, those were datacenter quality instead of consumer and worked great.
Got a letter in the mail a month ago that they had sent the broken account to a collections company in the US.
Of course for larger deployments you'd have to take care of fail-over and all this, so it's not really an option unless you are up for setting this up all by yourself.
So, if you're using software on the server which mucks around with firewall rules (eg using OS provided firewall on the server isn't good enough), then you're sad out of luck.
And their current IPv4 firewall has a 10 rule limit per server, which can't be raised. Mind boggling. :(
I've asked Hetzner if they have any plans to extend their firewall to include IPv6 support, or raise the # of firewall rules, but they have no plans to at this stage. :( :( :(
E.g. `docker run -p 8080:80 nginx` will expose the container's port 80 as port 8080 on the host. That port will be open whether or not the host has a firewall configured to block 8080.
You can do `docker run -p 127.0.0.1:8080:80 nginx` to only have the port on the host accessible on the loopback interface (for example if you have a reverse proxy on the host, proxying to 127.0.0.1:8080).
Docker is the stand out case from my point of view, and the ways it breaks networking seems to randomly change from version to version without warning nor consistency.
What are the well documented ways of using it properly, that avoid this weird behaviour from Docker?
Of course. That's why we do only bind them to localhost, and tend to use nginx to proxy from that to the outside world (for web apps anyway).
That being said, I've still seen Docker do dumb stuff with port mapping, and seen it change behaviour between "minor" version updates. Though that was a while (few years) ago now.
> ... except by not using docker
Kind of stuck with it for now, and having to work around it's crappiness. ;)
Of course you'll lose access to your server if the OpnSense VM breaks or doesn't boot up for whatever reasons after an update or so, but after 2 years I haven't had any problems. But in case something goes wrong Hetzner offers some nice recovery options, even if you don't have internet access to you server you can access your volumes in some kind of VM and get access to it via a VNC like interface (I had to use this feature a few times during the initial setup which consisted of a lot of trial and error I locked myself out a few times).
I wouldn't run this setup for anything mission critical of course, it's way too hacky and an official firewall solution would be better, but for my personal purposes as a "home lab" like setup it works perfectly fine so far.
* https://github.com/rootless-containers/rootlesskit/issues/25...
* https://github.com/rootless-containers/slirp4netns/issues/25...
This has repercussions if you need to be able to see the user's IP for throttling, banning, etc.
Which is why I'm very happy over this move by Hetzner. More monetary incentive to move away from IPv4 is exactly what we need to break the cycle of "nobody uses IPv6, so nothing supports it, so nobody uses it"
It's not really a solution to the problem, it's usually just ignoring the problem and hiding the symptoms.
I'm surprised Hetzner is the first to do this, it's an obvious move with the sharp rise of IPv4 addresses. Most companies don't need IPv4 anyway, because their infrastructure usually ends up at a caching proxy or CDN regardless. Your backend API servers will usually also be talked to by other servers, which usually also run from a place with widespread IPv6 addresses.
I can see a (bleak) future where consumers are all om CG-NAT and everything but the frontend is running IPv6 as a cost cutting measure.
sounds like business as usual
Many people are pretty adept at making sure the fingers don’t point at them.
But you don't any more, and prices are increasing fast: https://docs.hetzner.com/general/others/ipv4-pricing/
Useful for HA clusters, mostly. Free, too. https://docs.hetzner.com/cloud/placement-groups/overview
I'd assume you might be able to tell them to please put them on different racks for HA purposes, or something?
Is there any best-practice for IPv6 VM host setup? I found the IPv6 First Guide [0], but I'm not entirely happy with the bridged networking to VMs being used.
But they will probably just up prices for the end users.
Though I think mobile providers are already having a lot of IPv6.
Unfortunately, they use CGNAT which is a nightmare for anyone who uses the internet.
I pay them £5 per month to lease an IPv4 address rather than sit behind the CGNAT sharing the IP with all of my neighbors.
> In addition to the continuous optimization of this solution, we are also already working on being able to offer cloud servers optionally with IPv6 only. Here we still ask you for a little patience!
https://forum.hetzner.com/index.php?thread/28691-ipv6-only-f...
If your app servers need to talk with external IPv4 services you can run a box with an IPv4 and an HTTP proxy.
* https://docs.hetzner.com/general/others/ipv4-pricing/
Prices for IPv4 addresses went from US$30/IP in May to about $50/IP now:
> "We will continue to improve this new solution and are already working on an IPv6 only solution for cloud servers, too."
I'm eagerly waiting especially for this! The cloud servers are pretty cheap, but costs for IPv4 addresses make a significant part of the monthly cost. The Hetzner cloud server would be much more interesting if they weren't each tied to a public IPv4 address.
Looks like this will save you €2.02 a month.
I do hope they will start providing cloud instances without IPv4 soon too (they say they are working on it).
[1] https://docs.hetzner.com/robot/dedicated-server/ip/faq-prima...
They really do not give a f** about potential costumers.
I went with Server4you and they happily welcome me everything I book a new server.
If you can't show me a static blog post without this "DDoS" protection bullshit then I am just going to take a pass on your service.
It's bad enough that Cloudflare (and their users) think this is acceptable.
I had to click through to the FAQ to read about additional cost for IPv4, but there the difference isn't specified, so it led to more questions, but I gave up.
Reminded me of this other front page item: https://gds.blog.gov.uk/2013/07/25/faqs-why-we-dont-have-the...
>Primary IPv4 €1.70 monthly
Hetzner didn't used to let you drop that item off. Now they are letting you do that if you don't need a primary IPv4, and are happy with just IPv6.
edit: this is only for dedicated servers, not VPS's :(
The only competition to GCP there is IONOS where you cannot easily change your instance type!
And if you are making something interesting that utilizes the internets USP, it will have real-time communication between your customers.
And in the US if users from the east coast connect to something with the same latency as users from the west coast that evens out the advantages.
If you are making a static homepage then of course it doesn't matter because what you are making could also be a book or even a stone tablet.
The content always comes from the older medium until the new medium figures out it's own content at which point the old medium dies. See opera, theater, radio, television, youtube, twitch, etc. etc.
The final medium is the open 3D action MMO, be it in VR or not.
5 years ago i decided to never work on something that could not be sold globally, it's a good decision because it leans into the future.
What if my website is for my business and I only expect UK users to visit?
In europe there are maybe 20 actors for each of the many central countries (Germany, Belgium and Switzerland)... in the US there are only 2 (that I could find that allows me to remotely get a VPS): GCP in Omaha and IONOS in Kansas City!!!
AWS only has regions on the coasts!
You also only use these low latency "edge" servers for real-time (encrypted if you have private data) and keep the database and patch data on your own physical servers as they are not latency sensitive!
Clouds have very expensive networking and disk costs compared to buying hardware and hosting it on your home fiber! But you cannot live on all 3 major continents (EU, US, and Asia)!!!
Eventually people will exchange VPS on their home fiber, if you live in central US or Asia and want to exchange a VPS (preferably redundant 2x locations and on fiber with static IP and lead-acid power backup) for home hosted VPS in Sweden let me know!
As for building something on the internet for only people living in the UK that is meaningless.
Central US in Iowa / North Central US in Illinois / South Central US in Texas / West Central US in Wyoming. (Plus all the normal locations on the coasts.)
(That's currently more Central US data centers than GCP which just has an Iowa and a Salt Lake City data center today. If you are keeping count.)
If you were meaning IPv6-only then yes that would be pretty bad.
However, this principle isn't really enforced on a technical level. Only some standards such as SLAAC actually require the network to be a /64, and since SLAAC isn't really relevant for servers, most cloud providers have been relatively stingy with their IPv6 allocations - at least compared to what RFCs actually recommend. (Which would probably be a /48 per customer, per region.)
The idea behind the /64 minimum was to make auto-configuration easier - you could just stick the layer 2 ID (i.e. the MAC address) in the second half and not have to worry about collisions or stateful assignment system like DHCP. Remember that IPv6 was designed in the mid-90's, so both of these decisions seem silly now - using the MAC would be a serious privacy issue (modern operating systems use a random ID which changes frequently) and DHCP is very mature.
Why not? Does it result in technical problems? I know very little about IPv6 (but I know that a /64 is an absurdly large network).
Genuinely curious what you might need more for (for a single server).
Think of it in IPv4 terms, it's like having the range 192.168.0.0 to 192.168.0.255 (192.168.0.0/24) assigned to your host. 256 addresses should be plenty of addresses, but you can't cleanly segment them into multiple ranges, like you could with 192.168.0.0/16: because you can have 192.168.0.0/24, 192.168.1.0/24, 192.168.2.0/24.
By having multiple, complete blocks of /24, you can easily assign them to different classes of IP interfaces on your host.
There has been some hardware that takes a bit of a performance hit when doing route lookups that are longer than /64 in the past, but if you're doing this all in software on an end host, that's not an issue.
Go ahead and divide up that /64 to smaller blocks for your classification purposes, you'll still have plenty.
but as you mentioned, there are a few roadblocks that say: you shouldn't
The client obtains the network prefix from the RA, and then the client tries to generate unique host address.
"" The IPv6 stateless autoconfiguration mechanism requires no manual configuration of hosts, minimal (if any) configuration of routers, and no additional servers. The stateless mechanism allows a host to generate its own addresses using a combination of locally available information and information advertised by routers. Routers advertise prefixes that identify the subnet(s) associated with a link, while hosts generate an "interface identifier" that uniquely identifies an interface on a subnet. An address is formed by combining the two. In the absence of routers, a host can only generate link-local addresses. However, link-local addresses are sufficient for allowing communication among nodes attached to the same link. ""
https://datatracker.ietf.org/doc/html/rfc7421 is helpful in understanding this.
Basically it explains that SLAAC RFC itself does not define the /64 limitation, but other RFCs that are relevant to network operation do.
""" The addressing architecture [RFC4291] [RFC7136] sets the IID length at 64 bits for all unicast addresses and therefore for all media supporting SLAAC. An immediate effect of fixing the IID length at 64 bits is, of course, that it fixes the subnet prefix length also at 64 bits, regardless of the aggregate prefix assigned to the site concerned, which in accordance with [RFC6177] should be /56 or shorter. """
> you end up needing Proxy NDP for your traffic to reach other subnets smaller than a /64 (e.g. a /80) if you have the /64 on your wan interface and carve it out
It sounds like we are in full agreement.