PikaPods – Instant Open Source App Hosting
pikapods.com
pikapods.com
Even though this clearly target FLOSS-friendly users, which are already aware of stuff, they don't necessarily know all the floss services. So my recommendation would be to make an additional, more opinionated pod page (but I've never made a product in my life, so my advice is probably not worth much): - Show ""competing"" proprietary services in front of the pods, for people to maybe better understand what it is about - Make a subset list of ""recommended"" services, photoprism/photoview are redundant, developer/sysadmin stuff should probably not be listed, pick just one RSS aggregator (I personally use TinyTinyRSS which has a great Android appif I can add my own grain of salt)
Thanks for the product and I wish you good luck
Hoping to expand FOSS financing over time. The revenue share won't be enough, I think. So I want an optional sponsorship option to directly support the project. And maybe get a direct line to developers with this. Still early days for this.
I do know that people are willing to pay for the FOSS they use when it's convenient and when they already pay for something. Our other service, https://www.borgbase.com/ has shown this and we collect significant amounts there to support upstream development.
Also keep in mind that many projects aren't ready to receive payments. Either the authorship is unclear (forked many times), they can't/won't issue invoices, just don't want payment categorically.
One thing that is not clear is the estimated costs - is that per app, or do you charge for the server and I can run multiple apps? I think $10 a month for something to power 50 or so apps (maybe I don’t use them all the time, if I do I expect things to get slow or you allow say 2 concurrent apps) would be great.
I think this sort of thing will encourage people to use foss instead of the big walled gardens. Maybe this is the real web3?
My idea is a bit different: most web apps probably just need something like a firestore DB (Parse I guess would do?) so you charge for that and then apps are just a JS bundle format. Like android you have a store but also allow direct uploads at the users own risk.
Yeah, the goal is to make running FOSS as easy as Google Photos, but with more privacy and community-maintained code.
Also hoping to channel some funds back to authors, but that’s more complex than expected. Just getting started with it.
First, storage isn’t encrypted and I can’t think of threat scenarios that require it, since we only use bare metal servers and control the drives. Wouldn’t add much benefit at the cost of higher CPU usage.
For your account, you can enable TOTP 2FA from Account > Password/2FA.
For our production servers, any admin access needs a hardware Yubikey.
IMO, FDE is easy enough to do, even if the users never get to do it themselves. It sort of protects the users from leaking their data in the event that a company goes out of business or someone breaks in to steal hardware.
I’ll do some testing for the next server to see how much overhead FDE would add.
Maybe there will be good demand for simple db like SQLite. Just a suggesion.
Goodluck
Any benefits to being incorporated/hosted there?
Pros/Cons?
Are you planning on including resource intensive media/other apps like Plex, Emby, Jellyfin, Sonarr, Radarr etc as well?
Also, I HIGHLY doubt you're "surprised" to see this posted here and elsewhere (like on Reddit: https://www.reddit.com/r/selfhosted/comments/ulm395/pikapods...) as this all appears engineered / deliberate with your involvement - I mean, your response is literally identical - which is fine and all, but transparency is likely a better approach.
Good hustle though.
I’m trying to stay away from apps with large piracy/abuse potential for now. Later they may go on a dedicated server in a friendly country like Netherlands.
If I understood correctly, this service only allows managed hosting from a curated list of services/apps? I assume that I cannot run my own docker containers. There are a lot of Run Your Own links/text, which made me think first that I could run my own, but instead it seems that I can choose what can be run for me.
Assuming this is OCI based, how are the containers isolated? Is it with cgroups and namespaces (because of rootless), but still sharing the kernel or are users placed inside separate VMs?
What about storage/disk/volume encryption? If I get allocated 10GB of data from the disk, does it have readable, but deleted data from a previous user? How is my data secured on the disk?
I currently have a usage pattern with Jitsi, which I host when I need to have a meeting. I use it a few hours a week and a minute/hour based cloud pricing from many providers are ideal for this. It is relatively cheap to launch even a beefy instance for only a couple of hours at a time.
I didn't see Jitsi on the list, but also the pricing is only listed as monthly. Is there more granular pricing?
What about more closed source software containers, like game servers? I didn't see those on the list. I'm pretty sure Minecraft, Valheim, Satisfactory etc. servers would bring more customers and make the service more popular.
What about managed databases?
I also saw Gitea, but not Gitlab.
Your offering seems to target somewhat similar audience to Linode's Marketplace. Linode calls them "one click apps": https://www.linode.com/marketplace/
Your pricing seems cheaper than Linode's, but is there any other advantage to use your service over theirs? Linode can even manage and configure DNS settings for custom domains automatically for you for their one click apps.
I like your website and it works well on mobile. This service also seems at glance like a great idea. I wish there was a bit more information to help me understand what this service does exactly and how it differs from the competition.
The isolation is with users and SELinux. There are no VMs as those are pretty heavy.
> the pricing is only listed as monthly. Is there more granular pricing?
Pricing is with hourly granularity, but shown as monthly for simplicity.
> What about storage/disk/volume encryption?
We run only bare-metal servers, so this is less of a concern unless you expect the whole server to be stolen. Data still needs to be accessible all the time.
> What about managed databases?
It's more focused on end users, rather than devs. So trying not to go overboard with very technical apps.
> I also saw Gitea, but not Gitlab. > What about more closed source software containers, like game servers?
Still many apps to be added. I also try not to compete with hosting offered by FOSS authors, unless they push other options themselves. Added a note on Gitlab on our feedback tracker: https://feedback.pikapods.com/
> Your pricing seems cheaper than Linode's, but is there any other advantage to use your service over theirs?
Linode seems to use VMs and asks you to make an install script. So it will be heavier than simple containers I use.
Hope I covered a few questions. There was a lot in this comment...
> We run only bare-metal servers, so this is less of a concern unless you expect the whole server to be stolen. Data still needs to be accessible all the time.
So, when I delete a file and it is marked as deleted in the file system and it becomes empty space, then when this same space gets allocated for someone else, they can just read my file from the allocated empty space. This doesn't require the server to be stolen or physical access, just someone else reusing the same physical/bare-metal hardware after me. Encrypting files/volumes/storage per user solves this problem. Leaving it unencrypted exposes my data to all other users of the system.
Here is some ideas on how Google handles this: https://cloud.google.com/docs/security/encryption/default-en...
I hope you re-consider encrypting user data.
This would be an issue if we would offer access to block devices. That’s not the case. The pod can only see the files and not read at the block level. Else every shared hosting setup would have this issue.
I’ll still look into it and see if there is any action needed. And the potential overhead for encrypting only the mounted user files. My feeling is that it’s pretty doable.
Thanks. Got my first pod running.
Another suggestion might be Minecraft. My nephews have casually said they'd like their own server.
A very attractive option would be some kind of "Try on PikaPods" button, if you can somehow muster a very limited free tier, that these projects can put on their READMEs. A few have that with heroku and it makes them way more approachable.
The pricing is very attractive compared to running these things e.g. on RDS+Fargate (~25x). Most people would probably run on Digital Ocean or Hetzner Cloud which is closer.
Currently the limitations are: a) they should run on a single https port; b) come with some authentication and c) publish a Docker image of sort.
There is already a "Run on PikaPods" button for our FOSS partners. Hoping to add it to more projects, so people can quickly start using an app.
Updates arrive a few days after they are released and if you keep the ‘automatic updated’ setting enabled. We do some rudimentary QA before deploying updates.
It’s definitely for long-term hosting. Many pods have been running for months (we had a public beta since around January)
Big fan of BorgBase (the other product by the same company), I have been using them for quite some time for different projects.
- I'd like to know what kind of payment methods are available before signing up.
- I'd LOVE it if this supported a prepaid payment option, where the service just stops if you run out of credit. (With an email alert, of course.)
Yes, it's prepaid and your pod will stop after a few notifications. You can optionally enable automatic top-ups to avoid this. Both possible.
Alternatively add a disposable one-time card. Many fintech apps provide those.
Still, as vendor, I'd avoid putting a random charge on your card and then pay the chargeback fee. Ouch.
I use Docker images, as provided by the upstream project. So you get the same experience as running it yourself, as well as quick updates.
1: https://docs.sandstorm.io/en/latest/vagrant-spk/packaging-tu...
1: https://docs.sandstorm.io/en/latest/using/security-practices...
One of the biggest things is that Sandstorm prefers to sandbox individual documents versus applications, which mitigates a huge variety of security flaws in apps. In most cases vulnerabilities in apps on Sandstorm are not exploitable when run on Sandstorm.
It also manages most authentication and authorization roles for apps in an integrated way, which requires more integration work than just spinning up a Docker container.
Feel free to hit me up if you want to know more, though it would be a lot of work to make Sandstorm work for your business model at this point. It's cool seeing others in the "make open source web apps user-friendly to run" space though.
I do want to point out that this is from 2014 and we don't use Docker at PikaPods. We use Red Hat's stack, which integrates better with other Linux tools, like SELinux and Systemd.
It'd be cool to see a service like PikaPods built around Sandstorm as the platform layer, but there's a LOT of work to do to make Sandstorm a good idea to run commercially, and since we aren't running it as such, nobody's really working on those things.
Try apps on PikaPods as an easy way to test what I want to self-host -> damn this is easy, not gonna bother moving, I’ll just stay in PikaPods