I wish my web server were in the corner of my room
interconnected.org
interconnected.org
I had a URL on my website called moo.html that wasn't indexed. My friends had it bookmarked, and when they visited it they got a picture of a cow, but it played a cow mooing in my bedroom. It was a nudge to come online and be social.
The End.
[Joe] what's up <a href="//example.net/?username=
[Jane] nm, wbu
[Joe] ">join my chess game?</a>
Which could show on Jane's screen, if there is no HTML escaping at all, as: [Joe] what's up
[Joe] join my chess game? (<-link)
The message of Jane's would have looked like it got swallowed because it was inside the HTML tag, but so long as Jane doesn't know what's up and ignores it, clicking the link instead, the owner of example.net would see a pageload of https://example.net/?username=%0A%5BJane%5D%20nm%2C%20wbu%0A... and thus learn that the other person is called Jane. Then again, for this to work it would already have to be on the screen of the person clicking the link, but not of the person who sent the link or there would be no point. So I feel like I'm still missing something.At least if you are this person: http://facebook.com/profile.php?=73322363
(This link redirects to the profile of whoever clicks it)
it might not even be that hacky to be honest. in some ways modern log aggregation isn’t that different, just insulated by more steps and safe guards. less moos though.
The school I was in had to do a complete wipe of 5 TB of random shares (back then that was a lot of data)
and they expelled a bunch of students for pirating and hosting extreme content
After that the network filtering was standard policy.
They were "testing the newly pulled fibre optics" by trying to saturate it with Wow, Diablo, Counterstrike, Doom, Quake, etc.
They would book the computer labs of 60+ computers and tell everyone to boot up a copy of (ahem pirated) Half Life and get everyone one on games and then run a traceroute/ping/packet trace, etc to measure what was happening.
Those were the days...
Lots of pirating but also, thanks to it having a public static IP, a fabulous way for me to learn all about running and configuring my own web server, irc server, mail server, dns server, ftpd etc. etc. It was my gateway into experimenting with linux, discovering luminaries like DJB & RS, learning about RFCs, appreciating the open source/free software movement and probably a major reason why I ended up on a sysadmin/ops/infra trajectory after uni that still serves me well to this day.
A few of my customers were running legit and decent sized businesses and they had no idea it was being hosted by a college kid who actually wasn’t even monitoring things all that much. When I encountered a problem I couldn’t figure out from searching the internet, I’d usually just write some script and cron job to restart the service periodically. It also served as my everything (nameservers, support, e-mail, etc) so I remember one time there was a fire in my data center and it went down for about 36 hours. I had no way to communicate with my customers and the site was unavailable. Luckily I think only about 10 customers even noticed.
The light was controlled by an X10 "firecracker" module. Neat stuff, for the time.
Anyway, she would do that to get my attention if I wasn't by the PC and she wanted to chat via ICQ.
I still have the modules around here somewhere!
No native serial ports, though, and the restriction of things needing to be on the same circuit kind of puts a damper on things. In my college dorms everything in my room was on the same circuit.
re: the serial ports - If I remember correctly the signaling to the module was done on handshake pings (because serial data could "pass thru" the module). They'd probably be pretty easy to bit-bang from any 5V logic source.
As a high school student I helped my school do some sys admin stuff, and one day I was stuck in a server(?) room while the guy who had keys etc. was away in another room and floor. So I ssh-ed into the machine he was likely working on and ejected the CD ROM back and forth until I caught his attention :D
Her sister caught on but couldn't prove it.
If you want to be dismissive, call it nostalgia — or point out that every generation feels this way about the way the world is compared to the way it was when they were younger.
But I think there is something truly broken in the world and I think people feel it too. The phrase that kept popping into my head when I was feeling particularly down about the way of things was, "No one would have chosen this." That is, in reference to the way the Western world is today.
Turns out there is a cron job that updates the locate command's index.
updatedbWe wrote it on the LAMP stack which gave us the full suite of whatever you could find on a Linux CD at the time.
Fancy graphs? No problem.
Send reminder emails? Sure boss! We dutifully started hacking and testing and hacking to get that function in.
To test, we decided to send emails to jackfrost, santa, and so on from our own sendmail server to the corporate mail server. It worked fine because we weren’t spamming it, we were just sending a few messages every now and then as we debugged.
Turns out there’s really a Jack Frost that worked for us.
He was not pleased.
We were amused.
I think we apologized, and I forget how we figured out he was a real person.
Well. Hacked as in someone banging their password list against an SSH server that only accepts public key logins, at maximum speed with tens of simultaneous connections, pegging the CPU (and I was running junk hardware, I found that 800MHz Intel Coppermine CPU literally from a mixed waste trash bin). Usually the scripts doing this had the decency to keep the attempts to something like 1 per second which would be unnoticeable.
The problem was that I only had mechanical hard drives back then and they would spin up all the time and make noise.
In 2001 I started to systematically search for the causes of the disk noises and document it at https://www.agol.dk/quietlinux/
E.g., I spent a lot of time finding out that CUPS was generating a new certificate every 5 minutes. Nowadays it is a lot easier to investigate things like that. Back then I was patching the kernel.
I did something similar when I lost my phone but it was still connected to the network. Ssh into it and `while true; do espeak "I am here"; done`. Related: http://bash.org/?5273
Then when we finally got inside, the car didn’t have a keyhole to start it at all. Ended up calling the rental agency that showed us how to invoke the magic sequence by holding the (empty) fob in front of the start button for a few seconds before pressing it. I guess it does passive RFiD or something?
Anyway, that’s the point where I decided modern cars are not my thing.
I'll leave it to readers imagination how long it took me to troubleshoot the issue.
Plot twist: It's a Ring doorbell and wi-fi is down.
Though I did have a Linux ppc box serving website under my desk in the early 2000s.. until they blocked port 80.
https://web.archive.org/web/20020124163137/http://www.linuxp...
If it had been a bit more reliable I would have kept using it but I had some issues with either the bell coil or the relay and it kept sticking. All in all the project ended up being more expensive than a wireless doorbell, but I enjoyed the experience (and the smartwatch notification when someone was at the door).
> [it should] be reliable if I kick a cable out of the wall
Right, if you want it to be reliable but also be able to cut its cables, then you will need a secondary host outside the home.
> or in the unlikely event that I get a bunch of traffic.
Are you serving media (music or video of more than a few seconds)? If not: DSL or mobile data (if your data cap allows) is fine for HN front page. Judging by the current page weighing 100KB, you can have 10 visitors every second at 1 MiB/s upload. (HN reaches that rate only in spikes, even at a top three position.)
> I’d also like it to be quick!
It's currently not quick at DigitalOcean (2 seconds for TLS setup, 12 seconds for HTML, 8 seconds for JavaScript, etc... 27 seconds total). It can only get better!
I can recommend something beefier than a raspberry pi, though, or at least than than the pi 1-3 speeds that I'm used to. I personally use an old laptop which is plenty fast for, well, anything you'd also ask of a daily driver, except it now doesn't need to render a GUI which speeds things up a lot. They can peak up to 100W depending on the model, but are usually very low power when nothing is being asked of them.
> Oh, and I don’t want to have my home network hacked.
Then install unattended-upgrades, put admin panels (phpmyadmin, wp-admin) behind basic authentication, don't host things you don't trust (random code written by 'someone on the internet' that has never been tested by anyone), put it in a VLAN if you want to be extra cautious, and you'll be fine. It never hurts to keep your phone and other systems on the LAN up-to-date anyhow so they should be secure as well, even if someone does get in.
It doesn't have to be this way! Put it on a pi and have fun, if not for your sanity at the very least do it for your second most valuable resource, your time. If all a person wants to do is have a website that plays a piezo buzzer when someone visits on your RPi, just write that damned code, they shouldn't feel the need to worry about all the nitty gritty when all that they wanted to do is have fun!
I think I've heard of some services like that...
If connected on wifi to your router this of course solves the "kick a cable out" problem too, even if the battery is really old you'll almost certainly still have a few minutes.
> Then install unattended-upgrades, put admin panels (phpmyadmin, wp-admin) behind basic authentication
I'd go as far as protecting the directory to only allow access from local network, and use wireguard to reach the machine.
It's likely a server in the corner of the room will cost more than a VPS, certainly in my country. A server drawing 25 Watts cost more than the $3/month I pay. (That said I also have a pihole running on a 1B - my parasitic house load is about 100W for the fridge, router, wifi, etc)
Or, you know, only allow access from the attached hardware and reach the machine the old-fashioned way: By walking.
Regarding costs, it's useful to know the cost of a watt: For my electric rates, the equation runs:
$0.11/Watt-month = $0.162/kWh x 730 hours/month / 1000 kilowatts/watt
So at least in my area the 25W server would not quite cost more than $3/month.(The landlord had installed these sensor-activated ancient bulbs in the hallway, where I pass through to to the cellar / power meter, and I was trying to track down this mysterious 100W that seemed to be always running, without fail. Turns out, it was only running when I was checking the meter! We then did the math with a better runtime estimate and still went out to buy LED bulbs at our earliest convenience. They're brighter than before (we erred on the high side), just as warm light, and use 2.5x less power.)
And yes, in my opinion we erred on the high side, but it's not far off from what the original incandescent (which apparently was 2x50W, measured).
Very true! Battery from like 2015 still manages to keep it running for about two hours I think, which is frankly amazing. I was constantly dealing with taking the battery out of the laptop when not in use (98% of the time, it was connected to a charger, either in a classroom or at home, so I'd need only to bridge the stand-by/suspend/sleep period in the train). At the time, it didn't seem to have an effect as the battery still decreased in capacity and I was disappointed with the results, but I gotta say, it is certainly doing a good job since then!
Unfortunately, external drives on the 'server' are not on uninterruptible power and having two of them in a btrfs mirror caused me more headaches than I like to admit. Even after I figured out which one had the more recent data after going out of sync, I misunderstood the phrasing of the man page and mixed up the arguments for the device to be recovered and the device to recover from. 2/7 would not recommend btrfs on devices without UPS, or if you don't want to shell out the money to buy three instead of two large drives so you can have a 1:1 disk image of the known good device before starting to operate on it (which is what btrfs was supposed to do in the first place, but alas).
> A server drawing 25 Watts costs more than the $3/month I pay.
With the screen and keyboard backlight and such turned off, it should draw less than 25W unless you're actively making use of it (and thus it being worth it), but yes that's ballpark correct.
I also get a lot more value out of it than what I expect to get for $3/month, though :). LAN speed transfers can be nice, no network latency (at least not beyond of your control) when you host a game server, access control is all up to you, dedicated hardware, you can choose to upgrade to 16GB RAM at will (perhaps you got a new DDR4 machine and have no use for the old DDR3 RAM that still fits in this 'server') without having to pay extra every month for those gigabytes forever, buying storage basically at cost price...
For me, that's the big challenge; all I have is home internet on a dynamic IP provided by one of the big cable monopolies in the US.
- Setup public IP updating. You server runs a daemon that updates the DNS record automatically. You can do that with NameCheap. ($)
- You can pay 5$ to have a digital ocean droplet that acts as a reverse proxy that just forwards traffic to your real server. ($$)
- You can pay for "entreprise" service and get a static IP. ($$$)
You would run a program on your system which connects to Cloudflare. The traffic goes to Cloudflare first, and then gets forwarded to your system.
But if you want to be accessible to the outside world, you need to direct your traffic outside; I don't see a substantial difference between routing your traffic through Cloudflare, Comcast, Equinix, or any other major connectivity provider.
And I would mostly agree so long as you're the only one who has access to said data. There will always be "ISPs", of sorts, that your data needs to pass through; that's simply how the internet works.
The nitpick about Cloudflare is that they are starting to act as a gateway to the internet. Maybe you can turn their fronting off if they start giving you trouble, or maybe your registrar also runs behind Cloudflare. Anyway, bit of a philosophical discussion how much power to vest in one company.
The real trouble is that their main offering involves giving them the private keys to your traffic. I don't know if that's also the case with this Tunnel product, but at least for regular websites, then they process your actual data, as with the bank example (a colleague at said bank was not happy).
I know of only one ISP in the Netherlands that uses CGNAT and there you can ask support to fix it, which takes them 24 hours. I learned that the hard way when wanting to have a gaming night, hosting a factorio server in my student room. No gaming night for me, or so the ISP thought while rubbing their hands. It took me a bit but I eventually managed to proxy the UDP traffic somehow, not sure anymore if I used hole punching or somehow encapsulated it in TCP and reverse SSH tunneled or something. (Edit: on second thought, pretty sure I asked the other participants if they had IPv6 -- they did not -- and then proxied the traffic from my server via IPv6 using iptables. /edit)
We are quite fortunate with having had an early ISP community that managed to gobble up all the IP addresses we'd need for a good long while, and our population is relatively stable compared to other parts of the world. I know not everyone is this fortunate. (Hello ipv6...)
Even in a place like Germany, it seems one needs to be a business connection to get this service, it's simply not offered for consumers at all that I could find in some town in NRW. This is why I'm so happy the Netherlands has ISPs like Freedom (successor of XS4ALL) and Tweak who not only care about being cheap. Even if you don't use Tweak or Freedom, I feel like it keeps the local competition sharp.
[0] https://openwrt.org/docs/guide-user/services/ddns/client
Try not to worry too much about what happens when your IP is reassigned before you can update the name.
I technically have a dynamic IP, as the ISP also sells an upgrade to a guaranteed static IP which I don't pay for.
However, I've been getting assigned the same IP consistently since 2013. I used to use a dynamic DNS service to keep track of it but stopped doing that since it never changes.
P.S. - I pay for a static IP from my ISP. Don't count on that never changing either. I know this from experience.
Most nameservers provide a REST API for updating records so this is very easily done.
import json
import requests
IP_API = 'https://api.ipify.org?format=json'
CF_API_KEY = # Cloudflare API Key
CF_EMAIL = # Cloudflare email address
ZONE_ID = # Zone ID
RECORD_ID = # Record ID for this DNS entry
resp = requests.get(IP_API)
ip = resp.json()['ip']
resp = requests.put(
'https://api.cloudflare.com/client/v4/zones/{}/dns_records/{}'.format(
ZONE_ID, RECORD_ID),
json={
'type': 'A',
'name': 'jellyfin',
'content': ip,
'proxied': False
},
headers={
'X-Auth-Key': CF_API_KEY,
'X-Auth-Email': CF_EMAIL
})But before that I created a service for looking up my ip address and hosted it for free at fly [1]. Then I setup a script in cron to update my dns every 5min if it had changed.
One day I will. In the meantime, could you please drop some links to some good introductory pages ?
Thanks!
From there, any device that connects to one of those ports or wi-fi networks will use the assigned VLAN. The access points are great because you can create several wi-fi networks and then the software provisions them to how ever many access points and switches you have, so you don't have to login to each one and set them up separately.
Any links I sent would be specific to Ubiquiti, but happy to do so if you plan to use their hardware.
Hell now I want to try this with two old but decent android phones - they would sip power and have a built in UPS and would blow a RPI out of the water speed wise. Throw a USB-C to Ethernet adapter on each and setup for HA (or if you were really lazy just a simple round robin DNS setup). Put one at a friend house and have them both setup with the free Cloudflare proxy thing and you would not even need to open any ports on your firewall.
This article is likely to give you a good idea of the architecture: https://developer.hashicorp.com/nomad/tutorials/load-balanci...
The only way I see to avoid a SPOF is with anycast, which I think involves running your own ISP to be able to arrange your own BGP sessions and announce at multiple locations.
Is this worth while to do? I'm concerned about using a pi, because micro-sd cards seem to be notoriously bad for corrupting data in less than ideal power situations.
Whether it could survive a lot of pageloads, like when submitting to HN and it gets traction, 100% depends on the blog software.
It won't run Wordpress well because that software is ridiculously heavy, and I frankly don't have good examples of database-based blog software aside from something I wrote myself. Mine still does multiple mariadb queries per pageload, so it's not as though it's extremely lightweight, but page generation comes out to a few milliseconds on a laptop with a CPU from 2012 inside. This software would survive the HN homepage easily.
I would estimate that anything that can handle >10 requests per second will survive the HN homepage, but if you're on the edge of 10r/s then perhaps it might be slower during the busiest minutes. If you would use static page generation (like jekyll, though I'm personally not a fan of how jekyll works it's the most well-known example) then the pi will definitely survive serving those static pages easily.
> I would like it to at least be a little nicer looking
The looks don't make it heavier or less heavy. Having a few style rules applied to the page is a few extra bytes per pageload, but they're not going to make the difference between it working or it not working.
Thin clients are perfect for such tasks. More powerful than a Pi, fanless, uses little power, and comes with a proper network card. Second hand HP T620s are cheap.
Also default security measures such as disabling root login via SSH, disable password login via ssh, use fail2ban (also works for wp-admin and the likes!), install/use firewall and only open services which you want to access from the outside.
One time we were supposed to be doing work during class, but everyone was on IRC chatting. The classroom was completely silent. Somebody wrote "somebody say penis" in the channel and the whole classroom started laughing at the same time, for seemingly no reason. The teacher was confused, it was a good time to be a 15 year old dorking around with computers.
Edgy...
Bunch of clowns :P
How long ago was this? You'd think the school had a strict filter on outside connections, especially to IRC servers.
I'll paraphrase myself from a few days ago[0]:
The reality is that we've let you down. Self-hosting shouldn't be any more complicated or less secure than installing an app on your phone. You shouldn't need to understand DNS, TLS, NAT, HTTP, TCP, UDP, etc, etc. Domain names shouldn't be any more difficult to buy or use than phone numbers. Apps should be sandboxed in KVM/WHPX/HVP-accelerated virtual machines that run on Windows, Mac, and Linux and are secure-by-default. Tunneling out to the public internet should be a quick OAuth flow that lets you connect a given app to a specific subdomain, with TLS certs automatically obtained from Let's Encrypt and stored locally for end-to-end encryption.
The technology exists to do all of these things, but no one has taken the time to glue it all together in a truly good UX (we're working on it). Pretty much every solution in this space is targeted at the developer market, not self-hosters.
(Because I've never heard of such a thing.)
It was not a server, not commercial, and not abusive. I was threatened with disconnection.
I doubt mine would say anything even if I pushed 100TB a month through it. All their congestion issues are on download side thanks to residential traffic being mosty download (netflix etc).
There's some previous work in this space and I've also dabbled myself[0].
I've also seen people mention that apparently the flash memory doesn't do well with server type workloads, but a lot of that could probably be mitigated with logging to RAM, using a CDN, etc.
1. GP quote: "Domain names shouldn't be any more difficult to buy or use than phone numbers."
2. Your quote: "federated social network of some sort on old android hardware."
Put 1 and 2 together.
The only reason Facebook exists is as a middleman between people trying to pass messages to each other.
If people could easily find each other and run trusted non-proprietary software: A. there'd be no ads B. all comms are direct so government agencies couldn't simply compel access from a single source
Google could also then provide a messaging app to use this service but if some other open source app were to become the defacto and make facebook irrelevant that is still a big win for google. Advertising $$ with one less big competitor.
If Google marketed this correctly then they could be seen as a champion of privacy too.
But I think a company that's similar in a lot of technical ways to Cloudflare but targeted towards self-hosters instead of developers could be successful.
I think it's important for self hosting solutions to not run Android or Windows: People tend to take those platforms out and about. But obviously the x86 server requirement is (currently) a big limitation for sure.
Not sure I follow. Those are the two most widely deployed operating systems. If you want people to be able to upcycle their old devices for selfhosting, I think that's where efforts should be focused.
I mean, technically we could probably eventually get Sandstorm and similar platforms on WSL? Android is radioactive garbage and nobody should go near it. Especially for an older device already abandoned driver-wise, you'd never manage to do anything secure or stable with it long-term.
Android doesn't currently support virtualization, but there's hope it will eventually, which should mitigate many security concerns.
1) I had to change their code to accept a release that is older than 30 days old. 2) It had me pick my domain, say it started, and gave me a sandcats URL to go to that doesn't work. Feel like something is missing from the installation instructions.
I wouldn't say its too hard for your dad to use, it's just poorly documented
2) This is kinda the hard part because it depends on where you are hosting it. If you ping your Sandcats address, does it return the IP of your server/location? Is there a firewall, router, etc. you may need to open a port or forward a port?
Agreed that the parent posts suggest this should be easier. It really probably should, but it's hard to do that securely without depending on some outside service. Sandcats and Let's Encrypt removes a lot of difficulty but CGNAT and port forwarding and stuff might be best defeated by autoconfiguring something like Tailscale or Cloudflare Tunnel.
"The installer will offer you free dynamic DNS and valid HTTPS via sandcats.io, a service maintained by the Sandstorm development team. "
GPG signature is valid. ** INSTALLATION FAILED **
The downloaded package seems to be more than a month old. Please verify that your computer's clock is correct and try again. It could also be that an attacker is trying to trick you into installing an old version. Please contact security@sandstorm.io if the problem persists.
Hmm, installation failed. Would it be OK to send an anonymous error report to the sandstorm.io team so we know something is wrong? It would only contain this error code: E_PKG_STALE [yes] Sending problem report... Submitting error report failed. Maybe there is a connectivity problem.
You can report bugs at: http://github.com/sandstorm-io/sandstorm
Yeah, that provision of the install script is absurdly paranoid. No one will ever actually try to perform a downgrade attack on Sandstorm. OTOH the time limit has had the side effect of forcing me to push regular releases over the last 5.5 years (since the company shut down). So, I hesitate to juts remove the check, for fear it will make me lazy.
I should have a release up in an hour or two, or you can edit the shell script as ocdtrekkie points out.
EDIT: Done. Installer should work now.
Edit: ref CGI, there's a few apps on there that do that as well (e.g. fish tank temperature monitor). Nice thing about a small private network is being able to do CGI scripts in bash/whatever without having to worry too much).
[0] https://wlog.viltstigen.se/articles/2021/05/02/mdns-for-linu...
Also, somepcname.local mDNS works on most operating systems today (once you grant firewall permissions to it; for instance, on Windows setting your home network as a "Private" network for instance when it asks Public or Private).
(How would you even add hosts to an iPhone or something?)
Besides DNS-based naming there is Multicast DNS (Bonjour/Avahi/ZeroConf) and NetBIOS naming (which still exist and works on most operating systems that have Samba or something similar).
In any case, you don't need a remote service like Cloud9 or Tailscale to any of this. Normal networking has done this for decades.
The next step beyond this is running a more capable DNS system in your home network. Generally this takes the shape of a DNS forwarder service running on a router or server. It could be as simple as a PiHole or OpnSense firewall, or however complicated you might want to make it.
You could have your own top level domain as well.
I use NixOS, so it was easy to make a function to abstract over the config. In each computer's config, all I do is specify a hostname. This function does the work (or really, some nixpkgs committer did):
{ hostName }:
{
services.avahi = {
enable = true;
nssmdns = true; # Allows programs like ssh to resolve .local domains via avahi
inherit hostName;
openFirewall = true;
publish = {
enable = true;
addresses = true;
workstation = true;
};
};
}I've got a domain, and I've added multiple A records pointing to IPs of servers in my 192.168.X.Y NAT. This has a downside thought, that with short enough TTL, you may not be able to access your server during intermittent connectivity problems.
I'm using letsencrypt through traefik for the certs.
- desired hostname and search domain(can be bogus though not recommended)
- DHCP server parameters with the router's IP as primary DNS
- DHCP static assignment for (each of)server(s)
- DNS static assignment such as "yourserver.bogusdomain.tld 192.168.10.10"
- (optionally) domain names, ddclient, certbot
"Proper" classical router/firewall OSs like Cisco IOS, Juniper JunOS, VyOS, RouterOS, OpenWrt, all easily do it like they do a cigarette, but good gamer routers and some NASs also can do it okay in many cases.
Similarly for printing, I would love a local web app that I could submit PDFs to and get a printer to print the pages. I could imagine scanning working in reverse. I tried googling a bit but alas it seems no one has done it.
This is why I was thinking that a plain web app with a known good driver could solve these problems.
https://www.geeksforgeeks.org/incron-command-in-linux-with-e...
Because inside the firewall are a bunch of phones and laptops and things that are accessing random webpages and running random apps; and (depending on your level of home network paranoia) maybe a bunch of internet-of-things things, or networked speakers, or televisions, etc., etc.
So even your basement server for home-only use really needs a cert, and client auth, and obviously needs to stay patched... lest it become a monster inside the firewall itself.
Laptops are awesome for servers since they have built in UPS's and are not very power hungry
It was a fun experience and got me started on my road to becoming a MSP
Did you get into your "hobby teaching" through your school sysadmin job?
Someday I'd like to chronicle how my homelab evolved, but at the end of the "laptops" generation and immediately prior to the "VMware on a desktop" generation, I had an old DEC (Intel), an AST, and a Gateway laptop, all running under my parents' couch.
It works with all NATs/CGNATs by connecting from the pi over a bidirectional WS connection. PI <-> WS <-> Cloudflare. SSL is done on the cloud, not on the pi.
Install any web server on the pi and "cloudflared" to proxy it.
https://developers.cloudflare.com/cloudflare-one/connections...
I used to run an IRCd on 56k where it would disconnect you after three hours. With two modems timed just right you could dial-back in to the ISP on the second modem just as the other disconnected and have about a near second of downtime with no connection loss. Some of the best Quake 3 servers I played on were on 56K; truely a magical expirence now lost.
And then the third-party doctrine applies and they can tap you without a warrant and nail you for your private friend message board where you discussed smoking a joint or getting an abortion, if cloudflare complies. A main advantage of self-hosted in the home is supposed to be basic 4th amendment protections.
It's illegal for the federal or state gov to read US mail correspondence or tap phone lines without a warrant and should be for digital stuff too, but the third-party doctrine totally undercuts it.
You install it to a USB, put the USB into whatever you want as a server, and boot it up from the USB. The OS and config gets loaded into a ram drive. You now have a linux server ready to go, with access to thousands of apps and add-ons (which are basically just open source things you already know on various docker containers).
So you can install postgres, redis, whatever, and you are off to the races if you want to host your own side projects. Or you can install Tailscale, plex, and whatever OSS dropbox / media server clones to have access to your media anywhere.
The magic is that it all 'just works' and has a nice web GUI to install and configure things, and you don't even need to know that Docker is handling all the things running under the hood if you don't want to. The only tricky bit can be mounting volumes from the various containers to get things working together, for which there are many many guides and youtube videos. You can always bring your own docker compose config if you you want to keep it in code.
The uptime for one of my servers was up to well over half a year, and only storm & power outage brought the server down...now I've got it on a UPS with automated safe shutoff (again configured in the web GUI, took about 5-10 mins) if power drops again.
Unraid just runs and is rock solid and stays out of your way for whatever things you want to run.
Micromorts: units to measure risk of death— https://interconnected.org/home/2020/09/01/microcovids
First words— https://interconnected.org/home/2020/10/12/first_words
State sponsored fashion— https://interconnected.org/home/2022/08/16/fashion
Speaking with dolphains— https://interconnected.org/home/2020/07/20/dolphins
Bottling the overview effect— https://interconnected.org/home/2021/07/20/overview_effect
I have a web server in the corner of my room since the beginning of 2004.
Besides being a firewall/router/switch and hosting a web server, it hosts more than a dozen other services, including an e-mail server, NTP server, DNS servers, DHCP & TFTP servers, etc.
In 18 years it did not have any down time, except for a few minutes every 3 to 5 years, when I have upgraded the hardware.
I could have upgraded the hardware less frequently, but I have replaced it whenever I could reduce the power consumption without decreasing the performance.
Now it is at the 6th hardware version. It has started as a big Pentium 4 pedestal server consuming over 200 W, but until now it has been reduced to an Intel NUC with a 4.5 GHz 4-core Coffee Lake U CPU, together with 4 USB to Ethernet adapters used to increase the number of Ethernet ports to 5, consuming not much above 10 W, while being much faster than the oldest servers.
A laptop has the advantage of incorporating an UPS, but I would not trust most of them with working 24/7 for years, like an Intel NUC, or preferably some fanless small computer (with an external UPS).
I wish I had that reliable of a power source. Even with a UPS, I've had tornados, snowpocalypse, etc where the power loss has lasted longer than any UPS I have.
Now, with only an Intel NUC connected to an UPS that could power a big server for a half hour, the NUC might work for a day from the UPS without having to shut down.
Where I live, the "snowpocalypses", which were frequent when I was a child, have disappeared completely. On the other hand, tornadoes, which were completely unknown previously, have started to appear, so they might become a cause of problems in the future.
It has cost me about $60 per month, which is significantly more than non-business connections of similar speed (currently around 400 Mb/s) cost around here.
Paying for a business connection has been the main expense for having my own e-mail and web server. Except for the first server, all the later upgrades have been done by reusing computers that had been originally bought and used for other purposes. With the quickly declining power consumption of the newer servers, the cost of the electrical energy has become negligible.
A Raspberry Pi is not a good choice for a firewall/router and/or Web server, but there are small computers similar in size and price, e.g. NanoPi R5S (fanless and with 3 Ethernet ports, including two of 2.5 Gb/s for LAN and one of 1 Gb/s for WAN; 2 USB ports can be used to increase the number of Ethernet ports to 5), which should be good enough for most people.
The idea is you'd publish on your own web server, and syndicate to other services that could maintain under pressure, etc.
I think that for many people, setting it up at home is "Good enough" and if you get slash dotted, well then you can deal with it at that point.
This was in 2001, so it’s meaning has changed significantly since then.
A single image was the top result for "Japanese robot death cat" or something on Google Images, so I was getting pounded. A quick robots.txt update and a few days later everything was calm again.
Small sites would get pissed when site like the nyt hotlinked and serve them pron instead.
Back in 2000-01 I had a box at home hosting a webcam pointed at my cats' food bowls. I was working a lot so I liked to see them. I could also make sure they still had food when I had an extended 36 hour work session. It just pulled still frames. I never did work out streaming.
I installed an X10 module and wired it up to a CGI so I could turn on the lamp by the bowls when it was dark. The click of the relay would reliably bring the cats to investigate. Hit the page, see blackness. Press the "Turn on light" button. Refresh the page and see the light on. Count to 30, refresh again, and one or two cats would be in the frame sniffing around the relay and food bowls.
Going back to BBS days:
I wrote a BBS "door" for a friend's board that captured a 320x200 frame from a composite video feed, stored it as a 16 color grayscale GIF, and sent it to the caller via Zmodem.
The frame grabber had some a crappy command-line program that required a keypress to initiate capture. I hacked the program to NOP out the loop and just immediately capture.
At 9600 baud or higher the download time for the GIF was pretty tolerable-- 30 seconds or less. If I recall properly GIF89 had better compression and sped things up a bit too.
The composite video feed came a surveillance camera in gym my friend ran downstairs. I added a call to a command-line VOC file player to play a chime out the speakers in the gym couple seconds before the capture began.
Later we added an option to allow the caller to upload a VOC file to be played in the gym and optionally receive 5 seconds of recorded audio from the gym along with their video frame.
Fun times.
This is a level of freedom that I wish we still had today. I'm not talking so much about the open source, "free as in speech" freedom, but more so about the "free as in simplicity" type. Nowadays it feels like I need valid TLS and a PGP signature just to host some service in my own home, the ecosystems around them having decided that the ability to tinker was (perhaps justly) a far second to security and correctness.
(For reference, I tried building and inheriting my own Terraform providers a few months ago. It's not possible to host them off plaintext HTTP, nor is it possible to skip TLS validity checks when downloading them, nor is it possible to install them without checking for a valid signature.)
You don't need all of that. You can just host. I was hosting back in the early 00s and it isn't any harder today. Actually its easier because most DNS providers now have a reliable API so I can have a cron update the DNS entries when my IP address changes. Back in the 00s I use no-ip.org and had a subdomain from them.
I'm basically the only user now. Its been a great learning tool.
Public access used to be through exposing the proper ports to the Internet, but now its through a Cloudflare tunnel and Tailscale.
When I was 15 me and my friends really liked playing online MMOs. We used to enjoy chatting on VoIP program, but this software required a server which all clients would need to connect to.
We always thought it would be cool to host our own servers for this VoIP software instead of paying someone else to host one for us so I decided to dig out an old computer and set it up in the corner of my bedroom to use as a server.
We got the server software installed and then realised we could probably sell these online if we knew how to build a website.
To cut a long story short, we ended up teaching ourselves how to create a website with HTML, which eventually lead to learning how to program in PHP so we communicate with the VoIP software programmatically via Telnet and send emails, then eventually how take payments.
It took us a few months in total, but we did it. And this back before YouTube tutorials or useful programming blogs. You were mostly trying to work things out on your own so it felt like a real achievement.
One of the best moments of my life was receiving our first paid subscriber. I'll never forget the night my friend called me to tell me the news. And this was back when us teens had pay as you go phones so it was odd to get a call - especially that late at night.
Funnily enough we probably used that old computer in the corner of my room as our server for about a year until one night someone hacked into it. Never really worked out what they were trying to do but they managed to install some remote desktop software on their because because I got woke up one night by the computer restarting then someone remotely controlling the computer. It was kinda spookey at the time.
As you can image we paid for a dedicated server in the end, but it was such a fun adventure and that's why I'm here on HN today. The idea a couple of 15 year olds could set up a server in their bedroom and make some money was really inspiring.
Things are different now I think. We were one of just a handful of VoIP hosts back then. Today we would be buried by Google and people would probably complain about the server taking 50ms too long to respond. You'd need to spend $1,000 on adwords and have EC2 instances around the world just to be in for a chance.
I think co's should seriously consider this or at least adding everyones development machines to the prod cluster during when they sleep, which is what we did to render movies when i was at Weta Digital. 1000's of developer machines are pretty valuable if put to good use.
In terms of my home server, I mostly point subdomains at it to test projects running on my laptop (via an nginx proxy_pass), or share photos/music with friends. I used to use it a lot more when I why working away from home.
Outside of web facing uses, it's nice to have a central place to store and retrieve files from multiple devices. I'm using a an older i5 Intel NUC, and it works great.
Because arbitrary ToS "violations" are a thing, and good luck getting that fixed with them.
Every so often I think about doing it again, but security paranoia keeps me from it. What if they broke out somehow? I could DMZ it I guess.
It can be a bit tricky with hairpin routing, but you can make the DMZ seem to be "on the internet" even to the home network.
Use tail scale or something similar for actual "access my home network from far away"
I do open ports, for NextCloud (to be able share stuff) and some websites. But Home Assistant is only accessible from the Tailnet for example, as are my ssh servers.
Once you use Tailscale you realize this is how a VPN should be, it's really something.
Whenever I was linked from Slashdot I would pretty much lose connectivity, so I started using Coral CDN, moved it to a colo, then to Linode, and on and on through some 6 or 7 providers as technology changed and I tried new things.
It's been 20 years now (just wrote about that last week), and I sort of miss those days, but on the other hand I really don't--keeping the server alive and secure (even in Linode) was a bit of a chore, so the writing was pretty much on the wall that it would eventually become just a set of static pages on an Azure storage account. Zero worry about keeping the site secure, no runtime issues, and plenty of opportunities to be creative (like this: https://taoofmac.com/static/graph)
And boy, do I have plenty of in-house web servers and Raspberry Pis to make up for it--but none are public, and I just have a couple of cores spinning on each major provider for toy projects.
What does this involve? Are you tunneling a browser through ssh? Are you doing development work?
Also, the status page is a rather beautiful bit of text. Did you do that yourself?
Yes, remote dev work is done mostly with Visual Studio Code Remote SSH[2] (but I wish something similar would exists for Sublime Text).
[1]: https://developers.cloudflare.com/cloudflare-one/connections...
[2]: https://code.visualstudio.com/docs/remote/ssh
Edit: Yes, I hacked together the status page, something similar welcomes me when I ssh into the machine.
Edit 2: Some benchmark here: https://pibenchmarks.com/benchmark/62022
And feel free to ask me anything.
This.
I run mine on RPi 3B+ with a 4 running the database. I reverse proxy to my site via a cloud VPS instance for $4 a month. I switched to the cloud after years on NO-IP when 1) I noticed my IP never changed and 2) my home IP address was public via a look up of my domain name.
On another 3B+ I have a VPN so I can SSH in .
Some day I will get around doing a roll-your-own-ngrok [0] so I don't have to open any ports but have yet to do it. I have done it for a project I was working on and I needed to make the local dev server accessible to a 3rd party. Pretty slick and saves a bunch of time and hassle from having to put the code on the server. (As an aside: Does anyone else dislike the term "grok"? For whatever reason it annoys the hell out of me.)
I really have nothing important on there and go months or years without doing anything to it then get a burst of creativity or what not and update the site or just tinker with it.
[0] https://jerrington.me/posts/2019-01-29-self-hosted-ngrok.htm...
If you're very concerned about privacy, frequently SMTP headers generally contain IP address info...
It's puzzling that email services don't redact the originating (often home/residential) IP address from authenticated clients for privacy reasons.
Shout out to Cloudflare, setting up an access protected tunnel took like 10 minutes.
Like HTML's marquee and blink tags, just because you can do something on your web site doesn't necessarily mean you should.
Long story short, someone apparently went to a non-zero amount of effort to hack my homebrew file-upload form.
Most people should be fine with an office mini-desktop like ThinkCenter Tiny line, sketchy(sorry!) Docker features on a NAS kit, or even an Amazonian Celeron mystery boxes.
Cox now blocks port 80, making LE certs harder to get.
The monopoly situation (enabled by regulators) means if you lose your connection you are probably offline completely. There are no alternatives or competition.
Even if you tunnel/VPN, uploading too much, even on a pay-extra “unlimited” plan, they will accuse you of running a server and threaten disconnection. This happened to me when I rsynced a few TB of photos offsite for backup.
AWS and heroku are quite expensive for small projects and performance isn't great. Dynamic IP is not a problem these days either (it's also quite surprising how infrequently your IP changes fwiw).
If you're looking for heroku like interfaces check out Dokku (or other open source PaaS platforms).
After this tier of usage I think I'd consider moving many things to cloudflare workers.
All of which are a lot of very interesting reasons why you can't just run a web server on your current phone with its current modern OS and expect it to have 24/7 up time even though it feels to you like your phone has 24/7 responsiveness uptime.
It's a solvable problem if there were enough interest: light web hosting is something that could be added to the list of system services that can wake the device from idle states (in similar ways to how notification services get prioritized, or trickle data feeds like Find My Services). It's not likely a problem that current phone OSes are incentivized to support, though, because there's currently no reason for millions of people to want websites served from their pockets.
Maybe one day there will be an interesting P2P data "hosting" protocol that would be useful for modern OSes to prioritize in that way.
Search for "fanless mini pc" on Amazon or whatever and you'll be surprised. There's a lot of cool devices available that are approximately the size of a phone, use very low power (under 15 W) like a phone, are under $200 brand-new, have wired ethernet built in, USB ports, HDMI ports, can run normal Linux, and unlike Raspberry Pi they are actually in stock.
Plugged it in, installed a Linux and gave it a static IP.
We're building out our bootstrapped startup on that box for $0 per month.
It's the fastest CI service I've seen in years, admin takes a couple hours every couple months, and the minimal webapp that no one visits yet is crazy fast.
He's named Blue.
We love you Blue!
The good: No monthly fees, extremely fast compared to small/medium/large instances, full control and we retain local access when the internet goes down.
The bad: I live in an (un)developing country (FL) without reliable power or internet, so I had to buy a UPS and still get occasional external outages.
Everything on it (that I care about) is backed up in Git or S3.
It's been a real pleasure to spend a few hours setting up my own thing and not having to chase a bunch of service deprecations, API changes and general bullshit that still seems to plague cloud environments.
Obviously, I wouldn't scale up anything huge with this "stack," but I have every intention of running it until we absolutely must migrate and I suspect we'll go a lot further than expected with Old Blue.
You can relive this feeling by seeding a few torrents. I sometimes check up on my torrents and try to imagine the person behind the Moroccan IP address grabbing my Drop Dead, Gorgeus discography.
Pretty much like how google, mail and social networking websites served as the gateway drug for client server apps and cloud server, Bitcoin/Lightning/Ethereum are increasingly looking like the gateway drug for home server apps and home servers itself. And Umbrel has completely convinced me of this.
What you ideally want is network segmentation, use VLANS and put devices in their isolated network, only allowed to talk to the router/firewall, which only allows incomming traffic and doesn't allow the web server to initiate connections to the internet, except for NTP, software updates and DNS (fixed ips).
Dont give into the fear. See if there are alternative power sources you can play with for your raspberry pi and see if there are creative ways to buy them (used, other countries, etc).
Re power sources, what can you do with a solar powere battery? Is there a diy system of power you can build? One that takes in mainline power when available, and solar or battery when not? talking about small hobby panels that can charge a battery during the day and discharge at night. I used power banks for that purpose.
In this context if my life style is under threat i want to life style even harder. I sold a car and instead of buying a replacement i will install solar panels. I know its a fortunate case but even if i can life style a little bit harder and lay less in energy then i will do so (not waste energy but say if it gets cut because of actions if a certain dictator then i can still plug my phone in to criticise said dictator … even harder).
tl;dr; i’d look for creative solutions just so i can stick my two fingers up to the current situation.
> The ROCKPro64 4GB board designated as LTS (long Term Supply) model, PINE64 committed to supply at least for 5 years until year 2023 and beyond.
2023 is almost here :)
http://src.gnu-darwin.org/ports/audio/festdoc/work/festdoc-1...
https://era.ed.ac.uk/bitstream/handle/1842/1032/Taylor_1998_...
I imagine an evolved version of this, where the computer speaks the location of every visitor, their OS, browser, etc. Maybe tied into an Ad Network you could get the visitor's name and address spoken aloud, maybe even their picture. Voyeuristically watching the people coming to your website, from your bedroom. Hmm, that one was cute, let's send them a message.
I put it under my bed, I installed Slackware on it (it was still the time when it took about 11 floppy disks to get it installed), started playing with Apache+PHP, I used to run a quite popular software development forum on it, later expanded it with a wiki, links to my projects (Github wasn't around yet) and a small hack game.
Two decades later, I still run my own web server in my room. I wouldn't put big publicly-accessible websites on it (I don't want my bandwidth at home to drop because somebody is downloading a lot of images or videos), a couple of Linode instances do a better work handling that use case. But I do use it to run my personal blog, my Nextcloud instance, my mopidy-iris frontend for playing music in the house, my Jellyfin server to stream my media wherever I am, my Miniflux server to keep track of the RSS feeds and podcasts I follow, Ubooquity to keep a collection of my ebooks, and much more. It used to run on a RPi, now I've upgraded it to a mini pc with 8 GB of RAM and 10 TB of physical storage attached.
It does really feel like it's your own space, in your own house, accessible from anywhere, with no storage limits and with nobody who can show you a bill for the storage, bandwidth or CPU that you consumed.
That's a perception shift I've never really had. Servers have always just been computers with dial up modems, then networks, then the internet, for me. I've always known that I can, if I want, have a node on the internet that I fully control. It's just not been a priority for me in decades now.
I bet it really is a bit of a rush for someone the first time they make it work.
The ec2 fronting technique I stole from the Helm home email appliance/service. Paying three years up front it worked out to less than $3/month.
I do recall that setting up port forwarding and NAT and both sides was the biggest pain (I do not regularly do network admin!), exacerbated by the fact that the client side is smartOS which uses a different system (ipfilter) than linux (iptables) so there were two cryptic network filtering DSLs to learn. The VPN part was relatively easy as it's just a point to point connection with the local machine as the client, configured to reconnect when the connection is lost and on boot.
On the ec2 side this is (approximately) my iptables setup (1234 and 5678 are stand-ins for ports I use to ssh into the local machine from anywhere on the internet, I have two because there are multiple (smartOS/Solaris) zones on the machine):
sudo iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp dpt:http
ACCEPT tcp -- anywhere anywhere tcp dpt:https
ACCEPT tcp -- anywhere anywhere tcp dpt:1234
ACCEPT tcp -- anywhere anywhere tcp dpt:5678
Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT tcp -- anywhere ip-10-4-0-2.ec2.internal tcp dpt:http
ACCEPT tcp -- anywhere ip-10-4-0-2.ec2.internal tcp dpt:https
ACCEPT tcp -- anywhere ip-10-4-0-2.ec2.internal tcp dpt:1234
ACCEPT tcp -- anywhere ip-10-4-0-2.ec2.internal tcp dpt:5678
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:http
On the ec2 side, openvpn conf: dev tun1
ifconfig 10.4.0.1 10.4.0.2
verb 5
secret local.key
cipher AES-256-CBC
keepalive 10 60
persist-tun
persist-key
On the local side, openvpn: remote [ec2 ip adr here]
dev tun1
ifconfig 10.4.0.2 10.4.0.1
verb 5
secret ec2.key
cipher AES-256-CBC
keepalive 10 60
persist-tun
persist-key
On the local side, ipf conf in ipnat.conf. This is abbreviated as most of the stuff in there is just forwarding amid the zones which is not relevant to a simple linux setup without zones. In addition to figuring out the iptables equivalent I believed you'd want to replace the 102 adr (which in this case is a zone) with your local machine (like 0.0.0.0/0 or whatever): map net0 10.0.0.102/32 -> 0/32
map tun1 10.0.0.102/32 -> 10.4.0.2
(not sure if the first line is even relevant or not, it's been a while)If you can you should host your own blog/website on your own physical computer at home. Especially for blogs, availability and redundancy is just not critical. And if you do a little bit of preparation you can recover quickly from any failure. It is fun, you may learn a few things and it makes things more tangible. (Maybe dig into VLANs or a firewall with multiple interfaces that allows you to separate your home network from the server)
My blog is a static HTML site and it has survived many HN visits of 20k+ visits on a Raspberry Pi3b+. It has since been upgraded to a Pi4 but it doesn't really matter. My 50Mbit upload capacity was never really taxed at all.
I'm currently working for a customer fighting the Azure cloud and it's abysmal in every way possible. The simplest tasks of provisioning resources take forever to complete. It makes me fond of my 8-10 year old 20-core DL380 server that allows me to spin up a huge infrastructure in the same time Azure can spin up a small web app.
[0] https://louwrentius.com/this-blog-is-now-running-on-solar-po...
I recently put a 4TB 7200RPM Seagate hard drive into my dev box, split it into multiple partitions and mount them on /var/lib/docker, /var/lib/rancher/rke2 and a local nfs server (that used as an nfs persistent volume in my local rke2 kubernetes installation), and it's loud! It's like I'm going back to the 2000s. Accessing any services hosted in the local kubernetes platform or building a docker image would trigger a storm of clicking noises. Heck, even during idle, kubernetes is pretty chatty and would trigger clicking noises every so often.
I also had an instance of home assistant accessible from internet, but it's on raspberry pi so it's silent. My ISP has cgnat though, so I had to route all connections via my vps through zero-tier.
Said server is mostly private use for me and a few other people. If I had need for a public one I'd probably rent something for $5/month first.
Oh wait. I am renting something for $5/month. It runs backup DNS and MX.
It's also possible to host a static website on IPFS and point DNS records to cloudfare or another public gateway to let them handle the web server part.
Do we have this already? No I think most superior experiences are saas and cloud hosted e.g Apple/Google. They own the hardware and the software stack. The current state of open source + raspberry pi is not appealing to consumers. It might be the right way forward but only if totally packaged together in a box you just plug in.
Huge undertaking. Entirely doable. Just requires the right motivation.
Oh and websites don't have to be on the public internet, using a tailscale like VPN with shared keys is a good way since they do magic DNS.
1: It was two T3 lines, but only half of the second line was provisioned, so ~67MBps vs today's 12MBps.
I still think you can go a long way with bare metal you might have laying around. I find hosted VMs to be woefully underpowered for their specs.
1.) Cable (DOCSIS 3.0) Internet connection with a dynamic IPv4 address. 2.) Registered domain(s) 3.) Domain hosted via Dyn.org (for quick updates in the event my IP changes) 4.) Linux-based firewall/router that runs ddclient (to update the public DNS records should my IP change, which is very rarely) 5.) All port 80/443 traffic is forwarded to an LXD container running nginx as a reverse-proxy, where TLS encryption/decryption is handled 6.) Unencrypted HTTP traffic is then forwarded off to whichever LXD container is hosting the actual site
Unless my Internet connection actually goes down (which is rare thanks to a good provider and everything being on a UPS), the site stays up.
Hope this helps!
And certainly not on a Raspberry Pi running Linux - it sounds like a day of frustration, trial-and-error, and many many google searches!
I would pay good money for (let’s say) a Pi with all of the hard work done - just plug it in to your router and it’s already serving pages online.
Edit: also, dyn.org doesn’t seem to exist?
Some subdomains dedicated to personal services etc. Web server just a part of the game, not them specifically.
Technically there are NO reasons to justify "cloud computing" despite claims, the only real justifications are business of some against others interests. There are no reasons despite all ipv6 issue to not offer global addresses etc. The real issue is that most people simply have next to no ideal about IT nor how to benefit from in in their own lives. Those who know have not much choice...
Products like the DreamCheeky USB gadgets (looks like they went out of business in 2017 https://web.archive.org/web/20170821050810/http://www.dreamc... ) or the more recent Diwoom Pixel Art gadgets could be used to signal activity. There are probably a lot more solutions to this problem if you have a server sitting on or below your desk ;-)
It's on a Raspberry 2 cluster:
Since 2016 i have my own database also hosted on the same cluster and coded from scratch:
We need to implement HTTP/1.1 with less bloat, a C non-blocking web server that can share memory between threads is probably the most interesting project for humans right now, is anyone working on that?
Now I have a couple of small devices for monitoring, logging, and sharing and run them behind ngrok. They're quick and easy and I don't have to set up anything else.
Disclosure: I work for ngrok (as of last year) but used it since ~2014 already.
I feel like this is what IPFS and similar are made for. I could see a home user appliance configured with something like that, plug it in and your site is up, unplug it and it was replicated to other opt-in hosts.
It's another pet to me: I have to make sure it has a constant supply of electricity and internet. And requires maintenance from time to time.
Some photos here: https://vedantsopinions.medium.com/eth2-node-at-home-without...
I would get so excited when people called up, I got to spy on what they were doing and if they were from far afield I chatted with them :) Those were the days...
I remember sending my first text on the first widely available Nokia GSM handset in the fall of 1994.
SMS wasn't advertised as a feature until the turn of this century when networks figured out how to charge for the service largely due to base station logging disk constraints of space and latency.
Work like a charm. I pay a (very) small amount extra per year to get a static IP address.
NNTP only has one purpose, sharing information (human to human). It's doubtful that any mission critical application needed it. Once IT saw that NNTP traffic had significant traffic and was throttling other traffic (or just expensive), they knew they could shut it down easily and therefore they did.
I remember people putting desktop PC in the lockers with ton of warez and P2P to the world with the ID of someone studying architecture or medicine.
> I’m pretty technically capable but I’m not sure I can be bothered.
All this sounds fun and a cool throwback, but it's also rather more work than I'm willing to put up with right now.
Still working through some things, but everything basically works the way it should. Firewalls might not be a bad idea to update though.
With all the leds and flashing lights I couldn't sleep.
I run it behind a cheapo VPS for geolocation reasons.
Nowadays I just run an RPi3, which is silent and takes very little power.
2. Add AAAA record from domain to RPi IPv6 address
3. Profit
long live the free market. free for institutional-entities to step on individual humans.