Show HN: Self-hosted CMS on serverless Cloudflare
github.com
github.com
Pages is essentially totally free. R2 is within the same pricing magnitude as S3. D1 is a very new product and afaik is still in beta and doesn't have production pricing yet; so be weary there. Zero Trust is less usage and more per-user, I think $7/mo/user.
We launched a big presale this year with an e-commerce app hosted on Workers, and we just barely hit the 5$ threshold for the paid plan. Did not use more services (other than DNS/proxy) though, so YMMV.
I've been looking for affordable hosting solution to serve multimedia files, e.g., podcast audio, which is typically the biggest part of cost for hosting.
Cloudflare R2 is an attractive solution. R2 doesn't have egress fee and the free tier includes 10 million read requests/month [1]. Is 10 million a big number? Yes, at least in the podcast industry. If your podcast has 10 million listens per month (or let's be conservative, "only" 1 million listens/month), you could already make big money [2] while still in the free tier of R2! In other words, whenever you'll pay for R2, then you become a very successfully podcaster :)
For other Cloudflare products that we use in microfeed
* Zero Trust (provides logins to admin page) [3]: 50 users for free - how many admins do you need? 50 users enough? :)
* Pages [4]: 100,000 functions requests/month for free. This should be enough for personal/small-business type websites.
* D1 [5]: No pricing info yet. But they'll likely charge by # of reqs/month.
* CDN / Firewall / Cache / DNS etc.: there are other Cloudflare products you can use for free.
Probably the biggest price you'll pay when using microfeed is your time :)
There are (almost) one-click SaaS solutions that save you time, but you'll pay with money.
There are multiple-click self-managed solutions that save you money, but you'll pay with time.
[1] https://developers.cloudflare.com/r2/platform/pricing/
[2] https://www.google.com/search?q=how+many+downloads+does+a+po...
[3] https://www.cloudflare.com/plans/zero-trust-services/
Are there any other CMS's that people are using these days? Perhaps looking forward to be using in 2023?
The big draw for me is it's just Hugo/Gatsby/Jekyll underneath, and the output files can be delivered anywhere that will host static files (CloudFlare pages does this really well, as does Netlify).
> Our team is working on a V2 product. See it at Tina.io (in beta).
I'm going to go ahead and say it's the same people.
I will try this out this week!
Shouldn't that be two seperate issues?
Traditional CMS you do the setup and plumbing in the server because you have full control
Static website hosting you prebuild a website and push it up all complied and done but in a standard supported format, do it easily can go to different providers.
There's not much in between, because you can't (easily) write code that is happy to run in two different systems controlled by other people with different plumbing under the hood... It's certainly doable, but the more you generalize the more complicated your code gets... and the less you can benefit from the vendor specific stuff (e.g. removing features that one side does not support ... Or adding code to use it if it's there -- which makes code even more complicated)...
Edit: and to the point of code complexity: if you did this all yourself in an alpha release, you likely would make a company/product like forestry (mentioned elsewhere in this discussion) because you've made something some people would consider somewhat or very valuable
ps. You might want to consider a donation to the internet archive, see [^2] - no affiliation, just a happy user.
[^1]: https://middlemanapp.com/
[^2]: https://archive.org/
https://github.com/subzerocloud/showcase/tree/main/cloudflar...
It uses templates with Twig, and it's very simple PHP so you can host it anywhere.
I once hit the frontpage of a big aggregator from my country and it handled like it was nothing from a very cheap shared hosting.
From my Linux Mint laptop, all it takes is to open my FTP on Thunar (which involves a click in my sidebar), and I'm navigating it like any other file system. Right click, create file, write & format my post, and save the file.
Viola, it's published.
Oh, and you can mix Markdown with HTML and JS in your posts. Less stuff you need to learn.
So you basically remove 99% of the attack surface.
This setup is also completely free since the content lives on GitHub and my static site on render.com (but any static site hosting will work).
And since it’s Nuxt based, it automatically also supports more advanced features such as tagging, advanced queries and filtering.
Can only recommend it!
I like the idea of having web content you can put up with minimal configuration and cost but we have to draw a line for that definition somewhere.
I think you can ask 3 people this question and get 5 answers to where the "self hosting" line is drawn...
I am not sure were I would draw this line myself :-)
microfeed uses Cloudflare Pages to host and run the code, R2 to host and serve media files, D1 to store metadata, and Zero Trust to provide logins to the admin dashboard.
@jacooper is correct that the term has been wrongly used by the creator.For example, if you run a Nextcloud instance and upload pictures there, then you are self-hosting your photos.
If you have no access to the code then it would qualify as being hosted for you.
Seems yes for rented servers like hetzner but gets more heated when it's about "serverless"
I think "not SaaS" sums up today's definition of "self hosted" although I could be mistaken.
Edit: Netlify Edge functions seems to be pretty much exactly what I'm describing (drop js/ts files in a directory, deploy with your static site). The only problem with it for me is it's not self-hosted. Serveless functions would work, tho the separate deployment adds a layer of complexity, and I'd have to learn CORS finally lol
https://docs.aws.amazon.com/AmazonCloudFront/latest/Develope...
From a 2016 post CloudFlare states they don’t block Tor traffic and don’t let their customers block the traffic either but they will put restrictions such as captchas in place [1].
To me, their 2016 post claiming not to "block Tor traffic" is disingenuous, since they are exceedingly hostile to it. I only ever experience Cloudflare as an obstacle and nuisance online.
I also deeply dislike their attitude and PR stand, which is essentially victim blaming and disrespectful of those who make different technological choices. Their message seems to be;
"We make an effort to sound sorry to those who are harmed by our
business model. But you are a minority, and we make a lot of
money. If you want to make an omelet, you gotta break some eggs. Now
get out of the road."This is a subset of a larger push-pull on the privacy needs of users vs. the integrity needs of service providers; the modern threat model is a lot more complicated than it was in the era where you could deal with an attack by black-holing an IP range. For example, Google's login flow requires (required? this may have changed) JavaScript because there are attacks possible in non-JS HTML that Google cannot protect against without using JS to do DOM inspection. Does enabling JS also allow for various privacy risks? Yes. But it increases user security.
Maybe your contribution will bring clarity to others. And moreso if I also add that this is precisely the moral arithmetic, and conclusion that technical necessity excuses harms, which is unacceptable.
But it's also harmful to the Internet at large (as in "all the users of the Internet") if service operators can't keep a service online because it's swamped by malicious users (or, arguably worse, it is online but the nature of its use is so badly understood by its operators that it's serving as a springboard for larger, more coherent attacks).
Services like Cloudflare allow operators to outsource the knowledge of how to mitigate those issues. This increases the total services that can be provided online by lowering the knowledge floor via specialization, which makes the Internet "bigger" (in terms of more things you can do with / on it).
I am looking from the viewpoint of someone whose privacy and opportunity are harmed, so of course I have my biases. :)
> But it's also harmful to the Internet at large
A good argument to try, but not sure this "nebulous" harm, as JS Mill might say, really works. For many reasons; "The Internet" hasn't been a coherent, level entity for some time now. No doubt you've heard the term "splinternet" - something to which I actually think problems like Cloudflare contribute. And there's an implication that a "service provider" somehow outweighs a single user. Which seems nonsense since many "services" are one man shows with a handful of users while there are some individual users of great prominence, power and value. Besides, the Internet in it's "virgin" (most unharmed) form might be said to be purely peer-to-peer. The nebulous harms you propose really apply to a certain "kind" of internet, supporting certain kinds of interests.
> Services like Cloudflare allow operators to outsource the knowledge > of how to mitigate those issues.
They are outsourcing action, not just knowledge. Like a private police force Cloudflare are actively (and literally) intervening in third party business and taking punitive actions against individuals based entirely on their judge, jury and executioner logic. That is a lot less innocent than you make it sound. The users are outsourcing their judgement, while swerving their responsibilities as netizens.
> This increases the total services that can be provided online by lowering the knowledge floor via specialisation, which makes the Internet "bigger" (in terms of more things you can do with / on it).
As we've discussed in these pages many times, and under many topics and titles, growth is not an unqualified good. Scale is not unquestionably desirable. Quality is rarely commensurate with either. So I am not swayed by the argument that having some of the network avoidably broken is justified by extending its size.
I, for one, have a blog that I don't use Cloudflare for. There's a risk that my system gets hugged to death and I don't know until my service provider either notifies me or cuts me. And from a certain point of view, I might be considered a negligent actor because I'm not collecting enough information to know if somebody has breached my blog engine and turned it into part of the Low Orbit Ion Cannon. But I've chosen to value user privacy.
Point is, trade-offs. I don't think I'm in some kind of moral right space for my decisions, I've made them based on the kind of reader I expect to get.
I see that many of your personal concerns stem from the wish to be a good netizen yourself.
FWIW, I deeply value these discussions. You've made some new points, noted and helpful for my research, thank you.