You may not need Cloudflare Tunnel. Linux is fine
kiwiziti.com
kiwiziti.com
* Exposing a server running on the home network (behind NAT on a dynamic IP) to the internet.
* Doing so by renting a cheap VPS and using wireguard to forward traffic to the server at home.
I love wireguard and use it continuously. My phone has always on wireguard to my home network so all my phone traffic goes through my home router/dns, I can access the various private servers I have at home, get dns based ad blocking etc. I use an ISP that give me a static IP so it was easy to set up. It works like a dream.
That said when I want to run a public server I just rent a VPS and run it on that. I don't want anything I don't own initiating connections to anything on my home network in any way.
https://www.ripe.net/publications/docs/ripe-690#4-2-3--prefi...
Edit: Which I could do as my ISP and mobile network both support ip6. Y'all need better ISPs :D
If only there was one around here, but alas, they're all basically the same 2-3 ISPs - a couple of main ISPs, then smaller ones who are just using their network and renting bandwidth.
Most of the home networks I use are still behind a NAT use a single ipv6 to interface the world and within the network each computer has an internally assigned ipv4 just in case some operating system may not be compatible with ipv4.
Still are many old routers using ipv4 only out there as not many people care to renew their hardware as long as their WhatsApp and Netflix works.
they would first ban the selling of new devices not compatible with IPv6, then forbid ISPs to advertise IPv4-only connections as "Internet", then ban the selling of new IPv4-compatible devices.
(In a few years we're going to reach anyway the point when IPv6-only connections (mostly in Asia) outnumber IPv4-only devices (mostly in Africa, which sucks because they're the least able to afford an upgrade, but then being forced behind CGNAT sucks too).)
Now, IPv6 (when properly implemented, which is another failure mode) comes with much better safety out of the box (like not being able to scan all the suffixes in a reasonable amount of time to find computers on the local network to target), but I'm still impressed that now we seemingly have hundreds of millions of personal computers "directly" connected to the Internet with at best only the OS firewall as protection (when one exists), and it hasn't resulted in major hacking issues ! (yet.)
There never really was any such thing as a safe network, but it used to be acceptable to assume LAN traffic was safe. Now we know you might be on airport wifi or a large corporate network with compromised systems and the OS and systems software needs to handle that.
I guess the hackpocalypse will have to wait for when low-end computers (like those in tvs, cameras, personal assistants, connected doorbells, home automation, refrigerators) - you know, "Internet of Shit" that you can't really expect to feature its own firewall (?) finally get upgraded to IPv6 ? (How does it look like today ?)
It's a coin toss on if BT will properly allow ipv6 traffic each time the router reboots.
I've had to make provisions to force ipv4 on my machines because although composer et al. runs fine on my vps and elsewhere, if it tries to access it via ipv6 at home it more often than not hangs indefinitely.
shakes head sadly in Brexit
Most people want ipv6 so they can get more ips / static ips, but from a legislation perspective its more about future proofing and staying relevant.
My statement was clearly the use case of ipv6 a direct answer to your question. Why? as in why would people want ipv6.
Anyway have fun playing dumb.
You forget about the opportunity cost that comes from our broken Internet where you cannot assume end-to-end network connectivity because you might have to deal with NAT and especially CGNAT ! (How many protocols end up overcomplicated (=expensive) and dead in the water because of that ?)
There's this goofy band of people that know just enough to bring their own router but don't understand why a misconfigured AAAA record can mess up the happy eyeballs algorithm and are convinced Comcast is "censoring" small business. It's funny and kind of sad to read comments from people who are certain their misconfigured networks are the result of some "international conspiracy" against them. That's probably why Comcast has it turned off on the routers they loan to customers.
https://old.reddit.com/r/tmobile/comments/97ifsv/issues_with...
I have the same network ISP for my apartment and they give me only IPv6.
I hate it.
You must not have met many ISPs.
you do need to look for an ISP that gives you a static ip which isnt even possible where i live
First, network overlays are not easier to setup than VPNs. Installing and configuring a network overlay client on every device is much more work than setting up a single VPN tunnel for every network you want to access. Overlay networks are just easier to plan because there is no planning. But they're not easier to implement.
Second, and far more important, meshing all your devices into a single flat network is dangerous. There is a reason why networks are designed with isolation strategies. Introducing an overlay into your networks breaks down these barriers for you, but also for an attacker.
The only overlay network that has built in firewall capabilities is Nebula. When I started configuring its firewall rules I found myself just recreating my existing segmented networks, but in a much more obtuse way. Instead of configuring a central firewall, I was configuring firewall rules on each device.
After all my research, I'm still running the same segmented network I was running before my overlay experiments. But I would like to give some praise to both Nebula and Yggdrasil. IMHO, these are the two most existing projects coming out of this space right now.
What prevents you from meshing the individual services on a per-need basis? The fact that they're overlays makes them even more convenient for such isolation.
> The only overlay network that has built in firewall capabilities is Nebula.
Are those built in firewall capabilities really missing from the other networks?
As far as I know, ZeroTier is more of a SDN that an simple overlay (That's what made me interested in ZeroTier in the first place). If conventional "L4 transport-layer" firewall/routing capabilites are enough for real networks, then ZeroTier SDN capabilities are probably enough for it's virtual networks. Granted, it doesn't have some nice built-in high-level generic "L7 application-level" firewall capabilities, but I don't trust those in the first place.
I do this for my personal web server, but also set up the network rule so that its SSH port is only reachable from my VPN.
IMO, this is super convenient. I can keep my public servers out of my home network (so clear separation of private/public networks), but still a VPN connection is required to log into any of my servers.
Here is exactly what I would do:
1. Sign in to AWS console (with my Yubikey).
2. Click "Lightsail > instances > <my-server>"
3. Click "Networking > Allow Lightsail browser SSH/RDP"
4. Click "Connect using SSH".
5. Do debugging!
In short, you can use cloud providers' web interface as an escape hatch. This just works as long as you manage the firewall using your cloud provider's network filter, such as Security Group, rather than, say, iptables.
Works even if you mess up the boot process somehow
Disclaimer: I work here
I have a setup similar to the OP and there's a really good reason for it: cost. For $2k in hardware (one time) and a VPS + electricity at $20/mo, I can run a 64 core, 192Gb, 24TB server. Let's call that $4400 over the course of 10 years. You would burn through that budget in roughly 1 month to get the same specs on AWS.
Obviously I'm neglecting the impact and cost of network, if it's a hobby you can just reuse your existing connection but you can always buy a dedicated line (and adjust the cost calculation accordingly)
In terms of security, you can mitigate the surface area by running a reverse proxy on the VPS. I've got nginx on the front line which does TLS then proxy_passes to my basement server at its wireguard IP address. So it's strictly limited to http, no direct database or ssh access.
I don't know if I'd ever run a "real" website this way but it's great for hobbies and side projects.
At least that was the case when I set up my home server rack ~2 years ago. (Though 24TB might be too much since server grade SAS storage is very expensive even when it's used. So what I did was to buy servers with as little storage as possible and then just put SATA HDDs that I can get for dirt cheap.)
Together with a full standing rack on wheels, I bought them for $600 cash (plus U-Haul rental to get it home).
My trick is craigslist in a city with datacenters (PHX). There are resellers here who buy used hardware from local datacenters and resell them to smaller businesses. I've had it running 24x7 for almost 3 years now and it is still going strong.
https://www.reddit.com/r/homelab/ has some good references for acquiring hardware for a home lab setup.
The closest I can get a disposed server with those specs is at least 8k
I got 48 vCPUs and 96GB DDR3 for <$300 in 2016 off eBay. It isn't the most powerful, but it was cheap.
I wonder how you build such a hardware with just $2k (3990x alone seems to cost $3.5k), but with €94/mon you can get 16C32T, 128Gb, 8TB server from Hetzner[1]. It has Zen 3 5950X which has better single core performance than your 64 core assuming that you refer to 3990X, and often single core perf is more important than total perf because you don't use all cores all the time.
I estimate such a configuration to be $2.5k. With $2.5k you can keep the server for 2 years, with network and electricity provided by Hetzner. Also you can terminate it and rent another, better server at any time.
I thank the death of Moore's Law. Compute power obsoletes very slowly these days. Back in the 90s I was buying new equipment every year or two.
My primary hobby server is now 12 years old and going strong. My youngest server is 8 years old.
Every now and then I start shopping for an upgrade but eventually decide I'll spend the money later. It's still good enough for my needs and works well.
I do not regret one bit going for this set-up, although my next step toward scaling this up is indeed going to be some sort of hosted solution, the primary reason being the BTUs and decibels involved in running an actual server from my apartment.
Running a search engine or not, anyone with a serious interest in programming should have a server. I really can't recommend it enough. The ability to run large jobs that chew through hundreds of gigabytes of data for weeks if need be, without considering the cost, that dramatically increases the level of ambition you can have in your projects.
* I had an idea for a re-skinned wikipedia. So I processed all 40 gigabytes of wikipedia articles from an OpenZIM file. Took a week. No big deal. Later I used the same corpus to calculate language data models. That's another several days.
* I had an idea a while back. It required me to screengrab 500,000 websites. So I wrote a python script. Takes anywhere between 0.5-120 seconds per site. It's still not finished by any stretch, but I'm up to about 322,000 screenshots now.
It's just great.
I think in you case colocation data center would be alternative solution.
Is the RAM ECC ? Are the drives in a RAID configuration? Is it kept in a server rack? What router, switch, and firewall are your using?
That 64 core server is probably sitting nearly idle most of the time. You don’t just spin up big systems on AWS and leave them idle. The whole point of cloud computing is the on-demand scalability.
You can basically spend nothing until a request comes in, and most hobby projects are low traffic.
For example, I found a project that runs plex media server encoding jobs as Kubernetes pods: https://github.com/munnerz/kube-plex
When you’re not encoding anything, you’re not running much compute.
I think I’ve heard of game servers that wait for players to attempt to connect before starting the instance. If all you’re doing is playing a multiplayer game with friends that instance is going to be off 20+ hours a day.
Still, I haven’t done any napkin math on what applications represent cost savings.
True, my system is fairly static. But it scales when I need it. As mentioned, it's for my personal use. "on-demand scalability" is a bullshit buzzword in this context. My goal was to buy a machine capable of several specific tasks.
> That 64 core server is probably sitting nearly idle most of the time > ... plex media server > ... encoding > ... game servers > ... that instance is going to be off 20+ hours a day.
Not those tasks :-) I have no trouble maxxing out my disk IO and memory, slightly more challenging to keep my CPU busy but it's keeping an average load of 4-8.
If you can't keep a machine busy, just turn it off. Simple as that. I would not have bought such a beast if I didn't have a plan keep it busy!
It’s the convenience of it that is the big selling point to me.
That said, a classic entry-level "sysadmin" job was just a "jargon translation" job between a vendor and the local implementation of the vendor's products quite often anyway. That doesn't have to be a bad thing, but I do think it makes for a waste of human potential just to keep the anonymous cogs of an organisation running.
As I get older, I'm less inclined to look into a DIY way to solve a technical problem. Even if it's "not too complex". When I was younger and had more time to kill (aka stay up all night) that was cool. Sometimes I just wanna get a full night of sleep and am fine paying a small fee for access to a tool or service that I don't have to maintain or think about too much.
If you're going to rent a server, why not just put your stuff there?
It's also a lot easier to show off demo projects like this - you don't need to copy everything to your VPS and figure out how to run it, you just need to have it running on your local machine (e.g. your development laptop) and let other people access that. Obviously that's not a great system for anything long-term, but if you just want to show a friend something you've made, it's quite useful.
Presumably the pi is just running Minecraft
A $5 VM from Digitalocean has 1vCPU and 1GB of RAM.
The VPS power bill is already paid with its price. For the Raspberry you have to pay the power bill.
Here in Germany we now reach 40 Euro Cents/kWh. 5 Watts 24/7 are 17.52 Euro/Year 10 Watts 24/7 are 35.04 Euro/Year. The Raspberry is somewhere between.
That is the reason why I replaced my Dell t30 Server with two Contabo VPS servers. I also don't have to worry about my ISP screwing up my connection.
Buy a high-endurance card or simply use external media if you have I/O heavy services you run on it.
> The VPS power bill is already paid with its price. For the Raspberry you have to pay the power bill.
True, but that cost is so small. Not sure if those German prices are accurate for most places, but where I live, it's nowhere near 0.40 EUR /kWh, so the cost of electricity per year is marginal at worst, unnoticeable at best.
> That is the reason why I replaced my Dell t30 Server with two Contabo VPS servers. I also don't have to worry about my ISP screwing up my connection.
Taking a look at Contabo (never seen them before), it seems their "Cloud VPS" is all virtual CPUs (not dedicated ones), so not really comparable.
* As someone else said, overclocking helped, and I had a reasonable passive cooling case to help there.
* I used Paper instead of the normal Minecraft server, and I ended up spending a decent amount of time optimising the configuration. Paper by default comes with a bunch of optimisations, I enabled some more, although I also disabled some that were interfering with the more technical areas of Minecraft that I enjoy more.
* Whenever things started lagging, I went on a killing spree for our main farms, and that tended to work well enough. Most of our contraptions were turned off by default, or designed not to be too laggy. I also restarted the server every night, which worked reasonably well as a sort of ultimate GC.
If I were going to do it again more seriously, I'd probably get a cheap mini PC and use that instead, but for what it was - me and a friend rediscovering Minecraft after having not played it probably in about 5-10 years - the pi4 held up pretty damn well.
One problem with these VPS is contention for physical CPU between multiple tenants. Lots of CPU context-switching. Kills performance. You can get dedicated-CPU VPS, but at that point you're basically renting a fraction of a real server and the prices tend to be high.
A $100-$150 old x86 workstation or server off Ebay will do even better (I run several things, including a Minecraft server, on mine, and it performs great for all of it), but your power use will be much higher than with a Pi.
This is also why dedicated instances are usually way better for performance-sensitive hosting compared to beefier VPS instances.
1: https://virmach.com/cheap-kvm-linux-vps-windows-vps/
I only need it's IP address and network, nothing else, to setup a stateless reverse proxy. Which I guess is the best use case for such VPS.
Are they good?
Keep in mind, you get what you paid for. Many low cost VPS vendors are also using low cost IDCs to host their hardware. Some of those IDCs might be heavily sanctioned by other online services (say, Google will always want to verify if you're a human if the IP of the VPS lands on the sanctioned range).
Other than that, they're fine. My VPS with Virmach has been up since 464 days ago, I consider it stable enough (again) for my application.
If you're interested in low spec VPS, I would point you to Low End Talk (https://lowendtalk.com/), which is a forum for low cost VPS vendor and consumers.
If you value the privacy / integrity of other data then that also is more protected.
Now I’ve never tested this with a public/high(er) volume service but it lets me pen test internal networks just like I’m sitting in the NOC. And my “VPS” host can handle dozens of simultaneous connections to dozens of endpoints. I have SSH listening on a non-standard port (eliminates 95% of the script-kiddie noise) and cert auth. That’s the only listening service on the VPS box.
I am familiar with some “TCP-in-TCP” problems but I’ve never had any. If it falls down, it just reconnects when traffic can pass again.
So what am I missing?
AutoSSH has been 100% reliable for me, with any lost connection restarting without conflicts, duplication, or error. My AT&T connection is definitely not five nines, so any tunnel needs to deal with restarts very well.
The only upside I can see is that it can protect against targeted attacks on the crappy modem provided by my ISP. But if such an attack is widespread it will probably hit me anyway.
I'd imagine these two points are much more important than DDOS Protection and Caching for most people.
Yes, it won't scale to a million visitors, but then again, your purse won't scale to a million cloud visitors either.
His simple static page seems to be taking the load of making the front of HN.
No, they didn't get the traffic of a modern Google, say, because not as many people were online, but they did receive as much traffic as an upper-mid-tier modern site, and served it with machines weaker than a lot of modern phones.
Just serving HTML and small media files is something computers are very good at, if you get out of their way.
in case my power goes out or something
Since I can use tinc in bridge mode, I can run tinc on the upstream server and on a local machine which then provides access to several physical machines without running extra software on each of those machines, which is particularly useful for machines that are resource limited, like my Macintosh LC II and LC III+:
It'd be nice if it weren't so difficult to get public addresses.
(Every time I see tinc mentioned, I'm frustrated 1.1 hasn't been released. I made contributions to it 15 years ago that still haven't been released.)
[1] https://www.tinc-vpn.org/pipermail/tinc-devel/2006-January/0...
You don't need to pay for an vps nor an extra IP, plus, you don't need to learn about tunneling software such as Wireguard or Zerotier
although clicking the pricing tab - it says hobby / personal use free / "For professional websites that aren't business-critical." - $20 /month
and "For small businesses operating online." - $200 / month
custom price for non-small business..
Although I did not see tunnel there specifically, and the tunnel page just has a 'download the paper' CTA - so it's hard to know what price one should be paying, on top of the first two things of course.
https://serverfault.com/questions/1098093/how-setup-wireguar...
The combination of wireguard + firewalls and the complexity of iptables is not intuitive at all...
IPv4 isn't cheap these days, so those two requirements are not as easy to attain. Given they specifically mention Hetzner who significantly increased their prices for additional addresses in the middle of 2021 I'm going to assume this page was written some time ago.
Using a single IPv4 should be fine - just port forward that over the VPN. Given most of what people want to publish this way these days is wrapped in HTTP(S), if you want something both local to the VPS and back on your home⁵ server, use nginx or similar as a proxy to split traffic by [sub]domain. You probably want SSH to both the VPS to manage it and to the proxied home server, but that can be done many ways using just SSH¹² or better still use wireguard to connect to the VPN from your remote location and simply route SSH to the home machine over its VPN connection³.
But using something like wireguard is the way to go, many similar examples use SSH tunnels which while fine for some things (I use them all the time) will have additional performance issues in some cases due to TCP-in-TCP congestion management conflicts, and do not deal with temporary connectivity blips (not uncommon on home connections) as gracefully.
----
[1] Though most of these suffer from the TCP-in-TCP issues, that might be less significant than for hosting an app or other service but you are already using wireguard/similar so why not use it some more?
[2] The pure SSH options, which have different [dis]advantages depending on key management, interaction with other tools that wrap SSH, and so forth, include: just manually double-hopping, using the -J option to jump through in one command, configure an alternate named host in your .config using ProxyCommand to configure the second hop, and at least one other that has slipped my mind ATM.
[3] I would still be inclined to have a pure SSH option available as well, in case the VPN is blocked if I find myself constrained by a funky network at a client/other site that isn't limited enough to also block SSH⁴
[4] If you want to go a little more hacky to deal with networks that block try SSH completely but are fairly open wrt HTTPS, there are a couple of options there. I've used shell-in-a-box previously though that seems to be unmaintained ATM, Bastillion may be a better option though I've not tried it myself. Be careful how you secure these tricks if you use them…
[5] I've referred to a “home server” throughout as that is the most common use for this sort of thing in my experience, but it all applies to any other situation where you want to host something on a box that is NAT encumbered and/or not on a fixed IP address.
Once the clients talk to the lighthouse to build the tunnel they communicate directly
When the NAT punching works it's great. However (AFAIK) there's no option to use the lighthouse as a backup for when NAT punching fails, and when NAT punching inevitably fails it just doesn't work, even when everything can talk to the lighthouse.
I've only used this on very conventional networks, so I haven't quite noticed this difficulty. With this in mind, it is a little harder to generally recommend.
I'm pretty sure this is true in China too. What point are you trying to make?
Those aren't really comparable. What does "reliability" mean in this context?
Empirically false.