How much can you get out of a $4 VPS?
alicegg.tech
alicegg.tech
Virtualized offerings perform significantly worse (see my 2019 experiments: https://jan.rychter.com/enblog/cloud-server-cpu-performance-...) and cost more. The difference is that you can "scale on demand", which I found not to be necessary, at least in my case. And if I do need to scale, I can still do that, it's just that getting new servers takes hours instead of seconds. Well, I don't need to scale in seconds.
In my case, my entire monthly bill for the full production environment and a duplicate staging/standby environment is constant, simple, predictable, very low compared to what I'd need to pay AWS, and I still have a lot of performance headroom to grow.
One thing worth noting is that I treat physical servers just like virtual ones: everything is managed through ansible and I can recreate everything from scratch. In fact, I do use another "devcloud" environment at Digital Ocean, and that one is spun up using terraform, before being passed on to ansible that does the rest of the setup.
Disk monitoring isn't too hard though. For hard drives, run smartctl once an hour, alert when reallocated or pending sectors grows quickly or hits 100. For SSDs, cross your fingers; in my experience with a few thousand, they tend to work great until they disappear from the bus, never to be seen again. Have a data recovery plan that doesn't involve storage of the data onto the same model devices with very similar power on hours --- power on hour correlated firmware errors are real.
Yes - but stupid yearnings to "do what all the cool kids are doing now" are at least as strong in those who would normally be referred to as "managers", vs. "employees".
outcome A) huge microservices/cloud spend goes wrong, well at least you were following best practices, these things happen, what can you do.
outcome B) you went with a Hetzner server and something went wrong, well you are a fool and should have gone with microservices, enjoy looking for a new job.
Thus encouraging managers to choose microservices/cloud. It might not be the right decision for the company, but it's the right decision for the manager, and it's the manager making the decision.
(As does being a consultant wanting an extension and writing software that works, as I found out the hard way.)
There's a disconnect between founders and everyone else.
Founders believe they're going to >10x every year.
Reality is that they're 90% likely to fail.
90% of the time - you're fine failing on whatever.
Some % of the 10% of the time you succeed you're still fine without the cloud - at least for several years of success, plenty of time to switch if ever necessary.
You're not a software company, fundamentally you make and sell Sprockets.
The opinions here would be hire a big eng/IT staff to "buy and maintain servers" (PaaS is bad) and then likely "write a bunch of code yourself" (SaaS is bad) or whatever is currently popular here (last thread here it was "Pushing PHP over SFTP without Git, and you're silly if you need more" lol)
But I believe businesses should do One Thing Well and avoid trying to compete (doing it manually) for things outside of their core competency. In this case, I would definitely think Sprocket Masters should not attempt to manage their own hardware and should rely on a provider to handle scaling, security, uptime, compliance, and all the little details. I also think their software should be bog-standard with as little in-house as possible. They're not a software shop and should be writing as little code as possible.
Realistically Widget Masters could run these sites with a rather small staff unless they decided to do it all manually, in which case they'd probably need a lot larger staff.
However, what I also see – and what I think the previous poster was talking about – are businesses where tech is at the core of the business, and there it often makes less sense, and instead of saving time it seems to cost time. There's a reason there are AWS experts: it's not trivial. "Real" servers also aren't trivial, but also not necessarily harder than cloud services.
But those agencies don't want to have to staff for maintaining physical hardware either...
But Sprocket Masters still has to have an expensive Cloud Consultant on retainer simply to respond to emergencies.
If you're going to have someone on staff to deal with the cloud issues, you may as well rent a server instead.
A solid dedicated server is 99% of the time far more useful than a crippled VPS on shared hardware but it obviously comes at an increased cost if you dont need all the resources they provide.
So far I haven’t noticed that if I spend more for the company that I also get paid more.
Source: almost thirty years of ops.
I really doubt this. The one theme you see on almost every AWS proponent is some high amount of delusion about what guarantees AWS actually provides you.
Yeah, sure. Nobody gets fired for buying from IBM.
Well, if large companies had any competence in decision-making, they would be unbeatable and it would be hopeless to work on anything else at all. So, yeah, that's a public good.
Sure, you can get something working on Hetzner but be prepared to answer a lot more questions.
Agreed on your last point of enterprise asking for this which again is just sad that these business "requirements" dictate how to architect and host your software when another way might be the much better one
Disaster recovery is a very real problem. Which is why I test it regularly. In a scorched-earth scenario, I can be up and running on a secondary (staging) system or a terraformed cloud system in less than an hour. For my business, that is enough.
Plus who doesn't want to play with the newest, coolest toy on another's dime?
There's definitely an argument to move (some) stuff off cloud later in the journey when flexibility (or dealing with flux/pivoting) becomes less of a primary driver and scale/cost start dominating.
Because the industry is full of people who are chasing trends and keywords and to which the most important thing is to add those keywords to the CVs.
The incremental cost of being on a cloud is totally worth it to me to have managed databases, automatic snapshots, hosted load balancers, plug and play block storage etc.
I want to worry about whether our product is good, not about middle of the night hardware failures, spinning up a new server and having it not work right because there was no incentive to use configuration management with a single box, having a single runaway task cause OOM or full disk and break everything instead of just that task’s VM, fear of restarting a machine that has been up 1000 days etc.
Sure, the actual pile of Go(o) that drives it can be improved (and it is indeed improving).
That said, the hard truth is that your approach is the correct one, almost all businesses (startups!) overbuild instead of focusing on providing value, identifying the actual niche, etc. (Yes, there's also the demand side of this, as the VC money inflated startups overbuild they want to depend on 3rd parties that can take the load, scale with them, SLAs and whatnot must be advertised.)
Ansible is imperative, it can work toward a static state, and that's it. If it runs into a problem it throws up its SSH connection, and cries tons of python errors, and gives up forever. Even with its inventory it's far from declarative.
k8s is a bunch of control loops that try to make progress toward their declared state. Failure is not a problem, it'll retry. It'll constantly check its own state, it has a nice API to report it, and thanks to a lot of reified concepts it's harder to have strange clashes between deployed components. (Whereas integrating multiple playbooks with Ansible is ... not trivial.)
And even if k8s puts on too many legacy-ness, there are upcoming slimmer manifestations of the core ideas. (Eg. https://github.com/aurae-runtime/aurae )
And now you’re suggesting that people use a “simpler” non “standard” implementation?
So of course you can implement a minimal complexity solution or you can use something "off the shelf".
k8s is complexity and some of it is definitely unneeded for your situation, but it's also rather general, flexible, well supported, etc.
> you’re suggesting that people use a “simpler” non “standard” implementation?
What I suggested is that if k8s the project/software gets too big to fail, then folks can switch to an alternative. Luckily the k8s concepts and API is open source, so they can be implemented in other projects, and I gave such an example to illustrate that picking k8s is not an Oracle-like vendor lock-in.
Kubernetes is fantastic! Whenever I see a potentially competing business start using Kubernetes, I am immediately relieved, as I know I don't have to worry about them anymore. They are about to disappear in a pile of unsolvable technical problems, trying to fix issues that can't be traced down in a tech stack of unbelievable complexity and working around limitations imposed by a system designed for businesses with traffic two-three orders of magnitude larger. Also, their COGS will be way higher than mine, which means they will need to price their product higher, unless they are just burning through VC money (in which case they are a flash in the pan).
Good stuff all around.
Obviously the same can be said for long running VMs, and this can be solved by having a disciplined team, but I think it's generally more likely in an environment with a single long running dedicated machine.
I always hear about all the great stuff you get practically for free from cloud providers. Is that stuff actually that easy to set up and use? Any time I tried to set up my LAMP stack on a cloud service it was such a confusing and frightening process that I ended up giving up. I'm wondering if I just need to push a little harder and I'll get to Cloud Heaven
With Cloud stuff you have more configuration to do because it is about configuring virtual servers etc. Instead of carrying the PC in a box to your room you must "configure it" to make it available.
The cloud is not easy but damn trying to get cooling and power efficiency of an small server room anywhere near the efficiency levels most big data-center publish is next to impossible as is multi vendor internet connectivity.
With the cloud all of that kind of goes away as it's managed by whatever data-center operator that cloud is running on but what people forget is that that is also true for old fashioned colocation services which is often offering a better cost/value then cloud.
And while it's definitely harder to manage stuff like AWS or Azure because it bleeds a lot of abstractions small scall vpc providers hide from you or that you dont really get with a single home server, it's not hard on the scale of having to run a couple of racks worth of vmware servers with SAN based storage.
Being able to say "I want a clustered MySQL here with this kind of specs" is much better (time-wise) than doing it on your own. The updates are also nicely wrapped up in the system, so I'm just saying "apply the latest update" rather than manually ensuring failovers/restarts happen in the right order.
So you pay to simplify things, but the gain from that simplification only kicks in with larger projects. If you have something in a single server that you can restart while your users get an error page, it may not be worth it.
I'm sure you can find example setup scripts online (configure autoupdates, firewall, applications, etc.), should be a matter of running 'curl $URL' and then 'chmod +x $FILE' and 'bash $FILE'. I didn't need configuration management (I do use my provider's backup service which is important I guess).
Something like this: https://raw.githubusercontent.com/potts99/Linux-Post-Install...
(seen in https://www.reddit.com/r/selfhosted/comments/f18xi2/ubuntu_d... )
DO databases have backups you can configure to your liking, store them on DO Spaces (like S3). DB user management is easy. There's also cache servers for Redis.
You can add a load balancer and connect it to your various web servers.
I think it took me about 30 min to setup 2x web servers, a DB server, cache server, load balancer, a storage server and connect them all as needed using a few simple forms. Can't really beat that.
If you have any more info or opinions then please do share.
Lots of articles around the internet about hardening a Linux server, the ones I've tried take a bit more than 30 min to follow the steps, a lot longer if I'm trying to actually learn and understand what each thing is doing, why it's important, what the underlying vulnerability is, and how I might need to customize some settings for my particular use case.
I'd love if you jumped into our Discord/Slack and brought up some of the issues you were seeing so we can at least make the experience better for others using Dokku. Feel free to hit me up there (my nick is `savant`).
Let me preface and say that I'm an application dev with only a working knowledge of Docker. I'm not super skilled at infra and the application I struggled with has peculiar deployment parameters: It's a Python app that at build-time parses several gigs of static HTML crawls to populate a Postgres database that's static after being built. A Flask web app then serves against that database. The HTML parsing evolves fast and so the populated DB data should be bundled as part of the application image(s).
IIRC, I struggled with structuring Dockerfiles when the DB wasn't persistent but instead just another transient part of the app, but it seemed surmountable. The bigger issue seemed to be how to avoid pulling gigs of rarely changed data from S3 for each build when ideally it'd be cached, especially in a way that behaved sanely across DigitalOcean and my local environment. I presume the right Docker image layer caching would address the issue, but I pretty rapidly reached the end of my knowledge and patience.
Dokku's DX does seem great for people doing normal things. :)
Hetzner has all of this except managed databases.
https://www.hetzner.com/managed-server
The webhosting packages also include 1..unlimited DBs (MySQL and PostgreSQL)
does it have automatic backup and fail over?
> With booked daily backup or the backup included in the type of server, all data is backed up daily and retained for a maximum of 14 days. Recovery of backups (Restore) is possible via the konsoleH administration interface.
But i get the impression that the databases on managed servers are intended for use by apps running on that server, so there isn't really a concept of failover.
If you are doing your environment config as code it ultimately shouldn't matter if your target is a dedicated server, a vm or some cloud specific setup configured via an api.
Doesn't really matter which one, the point is that you have one that can build you a new box or bring a misbehaving box back to a know good state by simply running a command.
A single drive on a single server failing should never cause a production outage.
A lot of configuration issues can be tracked down to self-contained deployments. Does that font file or JRE really need to be installed on the whole server or can you bundle it into your deployment.
Our deployments use on-premise and EC2 targets. The deployment script isn't different, only the IP for the host is.
Now, I will say if I can use S3 for something I 100% will. There is not an on-premise alternative for it with the same feature set.
The point of DevOps is "Cattle, not pets." Put a bullet in your server once a week to find your failure points.
For me, the allure of the cloud is not some FAANG scalability fad when its not required, but automatic OS patching, automatic load balancing, NAT services, centralized, analyzable logs, database services that I don't have to manage, out of the box rolling upgrades to services, managing crypto-keys and secrets, and of course, object storage. (These are all the things we use in our startup)
I'd go on a limb and say dedicated servers may be very viable/cost effective when we reach a certain scale, instead of the other way round. For the moment, the cloud expenses are worth it for my startup.
getting the equivalent reliability with irons is a lot more expensive than renting "two dedicated servers" - now you might be fine with one server and a backup solution, and that's fair. but a sysad to create all that, even on a short contract for the initial setup and no maintenance, is going to go well beyond the cloud price difference, especially if there's a database in the mix and you care about that data.
For many even lot less than that. I run a small side project[1] that went viral a few times (30K views in 24 hours or so) and it is running on a single core CPU web server and a managed Postgres likewise on a single CPU core. It hasn't even been close to full utilization.
Could I switch some of them to lambda functions? Or switch to ECS? Or switch to some other cloud service du jour? Maybe. But the amount of time I spent writing this comment is already about six month's worth of savings for such a switch. If it's any more difficult than "push button, receive 100% reliably-translated service", it's hard to justify.
Some of this is also because the cloud does provide some other services now that enable this sort of thing. I don't need to run a Kafka cluster for basic messaging, they all come with a message bus. I use that. I use the hosted DB options. I use S3 or equivalent, etc. I find what's left over is almost hardly worth the hassle of trying to jam myself into some other paradigm when I'm paying single-digit dollars a month to just run on an EC2 instance.
It is absolutely the case that not everyone or every project can do this. I'm not stuck to this as an end-goal. When it doesn't work I immediately take appropriate scaling action. I'm not suggesting that you go rearchitect anything based on this. I'm just saying, it's not an option to be despised. It has a lot of flexibility in it, and the billing is quite consistent (or, to put it another way, the fact that if I suddenly have 50x the traffic, my system starts choking and sputtering noticeably rather than simply charging me hundreds of dollars more is a feature to me rather than a bug), and you are generally not stretching yourself to contort into some paradigm that is convenient for some cloud service but may not be convenient for you.
There is a method to the madness, here it is called "job-security-driven development".
I suspect that VendorOps and complex tools like kubernetes are favored by complexity merchants which have arisen in the past decade. It looks great on resume and gives tech leaders a false sense of achievement.
Meanwhile Stackoverflow, which is arguably more important than most startups, is chugging along on dedicated machines.
1: https://stackoverflow.blog/2016/02/17/stack-overflow-the-arc...
It seems like the trend in this space is to jump directly to the highest layer of abstraction. Skipping the fundamentals and point to $buzzword tools, libraries and products.
You see glimpses of this in different forms. One is social media threads which ask stuff like “How much of X do I need to know to learn Y?” Where X is a fundamental, possibly very stable technology or field and Y is some tool du jour or straight up a product or service.
CORBA belongs there. And perhaps even the semantic web stuff. Definitely XML!
XML is great - if you don't believe it, then you might be interested in the pains of parsing JSON: http://seriot.ch/projects/parsing_json.html And don't get me started on YAML...
Have you ever had to manage one of those environments?
The thing is, if you want to get some basic more-than-one-person scalability and proper devops then you have to overprovision by a significant factor (possibly voiding your savings).
You're inevitably going to end up with a bespoke solution, which means new joiners will have a harder time getting mastery of the system and significant people leaving the company will bring their intimate knowledge of your infrastructure with them. You're back to pets instead of cattles. Some servers are special, after a while automation means "a lot of glue shell scripts here and there" and an OS upgrade means either half infra is KO for a while or you don't do OS upgrades at all.
And in the fortunate case you need to scale up... You might find unpleasant surprises.
And don't ever get me started on the networking side. Unless you're renting your whole rack and placing your own networking hardware, you get what you get. Which could be very poor in either functionalities or performances... Assuming you're not doing anything fancy.
If you want 100.0000% uptime, sure. But you don't usually. The companies that want that kind of uptime normally has teams dedicated to it anyway.
And scaling works well on bare-metal too if you scale vertically - have you any idea the amount of power and throughput you can get from a single server?
It's concerning to keep hearing about "scaling" when the speaker means "horizontal scaling".
If you requirements are "scaling", then vertical scaling will take you far.
If your requirements are "horizontal scaling on demand", then, sure, cloud providers will help there. But, TBH, few places need that sort of scaling.
I'm not saying 100% uptime on bare metal is cheap, I'm saying 100% uptime is frequently not needed.
I personally have run Dedicated Servers for our business in the earlier days but as we expanded and scaled, it became a lot easier to go with the Cloud providers to provision various services quickly even though the costs went up. Not to mention it is a lot easier to tell a prospective customer that you use "cloud like AWS" than "Oh we rent these machines in a data center run by some company" (which can actually be better but customers mostly wont get that). Audit, Compliance and others.
Because it's a threat to their jobs.
We went through a growth boom, and like all of them before, it meant there were lots of inexperienced people being handed lots of money and urgent expectations. It’s a recipe for cargo culting and exploitative marketing.
But growth is slowing and money is getting more expensive, so we’ll slow down and start to re-learn the old lessons with exciting new variations. (Like Here: managing bare metal scaling and with containers and orchestration)
And the whole cycle will repeat in the next boom. That’s our industry for now.
Today, cloud is similar - the time to market is quicker as there are less moving parts. When the economy tanks and growth slows, the beancounters come in and do their thing.
It happens every time.
This only makes AWS richer at the expense of companies and cloud teams
It is trivial to provision and unprovision an EC2 instance automatically, within seconds if your deployment needs to scale up or scale down. That's what makes it fundamentally different from a bare metal server.
Now, I'm not denying that it might still be more cost effective when compared to AWS to provision a few more dedicated servers than you'll need, but when you have really unpredictable workloads it's not easy to keep up.
if you are spinning up and shutting down VMs to meet demand curve - something is seriously wrong with your architecture.
Did it ever occur to you, how come stackoverflow uses ~8 dedicated servers to serve entire world and doesn't need to spin up and shutdown VMs to meet global customer demand?
--
When planning compute infrastructure, it is important to go back to basics and not fall for cloud vendor's propaganda
You said it yourself. Not all applications need to serve entire world, therefore demand will be lower when people go to sleep.
Even with global applications there are regulations that require you to host applications and data in specific regions. Imagine an application that is used by customers in Europe, Australia, and the US. They need to be served from regional data centres, and one cluster will be mostly sleeping when the other is running (because of timezones). With dedicated servers you would waste 60-70% of your resources, while using something like EC2/Fargate you can scale down to almost 0 when your region is sleeping.
IME aiming for scalability is exceedingly wrong for most services/applications/whatever. And usually you pay so much overhead for the "scalable" solutions, that you then need to scale to make up for it.
I only have one ansible setup, and it can work both for virtualized servers and physical ones. No difference. The only difference is that virtualized servers need to be set up with terraform first, and physical ones need to be ordered first and their IPs entered into a configuration file (inventory).
Of course, I am also careful to avoid becoming dependent on many other cloud services. For example, I use VpnCloud (https://github.com/dswd/vpncloud) for communication between the servers. As a side benefit, this also gives me the flexibility to switch to any infrastructure provider at any time.
My main point was that while virtualized offerings do have their uses, there is a (huge) gap between a $10/month hobby VPS and a company with exploding-growth B2C business. Most new businesses actually fall into that gap: you do not expect hockey-stick exponential growth in a profitable B2B SaaS. That's where you should question the usual default choice of "use AWS". I care about my COGS and my margins, so I look at this choice very carefully.
Peak performance is certainly worse - but I am not too bothered if something takes longer to run anyway. You are certainly correct on having as much automation in the provisioning of a server, something I did not do with a physical server.
I used to have a root server for my pet projects, but honestly, that doesn't make sense. I'm not running a high traffic, compute intense SaaS on my machines. It's just a static website and some projects. I'm down to monthly costs of 24€, which includes a storage box of 1 TB to store all my data.
AWS is very cost efficient for other services (S3,SES,SQS, etc) but virtual machines are not a good deal. You get less RAM & CPU, with the virtualization overhead, and pay a lot more money.
Especially for Postgres if you run some tests with pgbench you can really see the penalty you pay for virtualization.
Maybe the sysadmin skill of being able to build your own infrastructure is becoming a lost art, otherwise I can't explain why people are so in love with paying 5x for less performance.
Hetzner is cheap and reliable in Europe, if you're in North America take a look at OVH. Especially their cost-saving alternative called SoYouStart. You can get 4/8 4.5ghz, 64 RAM and an NVME drive for $65.
(I have no affiliation with OVH, I'm just a customer with almost 100 servers, and it's worked out great for me)
Self-serve infrastructure appears likely to become increasingly viable as we continue improving last mile delivery and expand fiber access. Will cloud become self-cannibalizing? Definitely maybe.
What cloud gets you is the ability to put your data/workload right at the core without having to make special deals with your local isp, and with a lot more resilience then you would likely afford unless your at least at the multiple 20 foot container full of servers scale of compute need.
https://www.cloudflare.com/products/tunnel/
https://github.com/cloudflare/cloudflared
https://developers.cloudflare.com/cloudflare-one/connections...
Edit: If anyone is interested in self-hosting, it's stupid simple with cloudflared. I have a 2017 Google Pixelbook running Ubuntu on custom firmware that's serving a Flask-based website. It sits on my desk charging while connected to a guest wifi network. It receives a 100/100 Mobile PageSpeed score and takes 0.8 seconds to fully load.
I'll also note that I'm old hehe, and one of my first jobs we had a decent sized data center on site. Dealing with SANs, tape drives (auto tape rotators at the time were garbage), servers, etc... was a huge PITA. Packing up tapes and shipping them to another office for location redundancy was always fun.
The particular application I manage really suffers from low GHz and not having all data in memory. Ive run the benchmarks on EC2, certain reports that finish in ~5 seconds can take more than a minute on a comparable EC2 instance that costs about 10x as much. This application really needs the raw CPU. and yes we have a pretty large engineering team that has optimized all the queries, índices etc.
As far as replication, backups, etc. I set all that up, and honestly it wasn't a big deal. It's a couple short chapters in the Postgres book that explain it all very simply, how to configure, continuously (and automatically) test, etc.
I do agree that SANs are a nightmare. Thats why I ship all my WALs (PG backup files) to S3 (and eventually Glacier). That way I don't have to think about losing those files and it's dirt cheap.
I think there's a misconception that these kinds of configurations are too complicated for a single engineer to setup, with never ending maintenance required. In reality you can set it all up in less than a week and it only really needs maintenance when you want to upgrade Postgres (some settings may have changed). I'd estimate it takes about 5 hours per year of maintenance.
Hetzner cloud now has two US locations... Still no US dedicated servers though - those would kick real ass. Even if their current cloud offerings themselves are already ~30% of the price of the major cloud equivalents...
From DO I get all the benefits of a reliable company, scalability, automated backups etc etc. There's no way I'd change.
The biggest additional cost to this is renting more IPv4 addresses, which Hetzner charge handsomely for now that there are so few available.
More info https://europa.eu/youreurope/business/taxation/vat/cross-bor...
I guess if I was investigating commercial options I'd have the "trunk" sorted at the office with a commercial isp solution, static IP, good IT hardware maybe, but from what I know at this exact moment if a client needed hosting I'd always go straight to renting a vps.
If you want ECC RAM, that appears to be €60/month, and it also steps up to a more powerful 8-core CPU.
Regardless, if we're talking about a "full production environment and a duplicate staging/standby environment" (to quote the person you replied to), then €60/month * (2 or 3) is still dirt cheap compared to any startup's AWS bill that I've seen.
Use cases vary, but I tend to agree that AWS/GCP/Azure is not the answer to every problem.
For someone who can fit their application onto a $4 VPS, that's obviously going to be cheaper than anything bare metal, but the cloud scales up very expensively in many cases. Bare metal isn't the answer to every problem either, but a lot of people in the industry don't seem to appreciate when it can be the right answer.
For a beginner, the cheapest ones get the work done.
I am sure that as cloud computing evolves, these offering become more common.
There is another aspect of cloud computing. The medium to large corporates, count cloud computing as single digit percentages on their cost calculations. This means that the decisions taken by managers and teams, often search for reliability and scalability (to be put on their presentations) rather than "is my setup costly or cheap".
Setting up and managing Postgres is a pain tho. Would be nice to have a simpler way of getting this all right.
There's a whole band of people who have the technical chops to self-host, or host little instances for their family/friends/association/hiking club. This small margin where you're ok to spend a little extra because you want to make it proper, but you can't justify paying so much and spend time doing hard maintenance. A small VPS, with a shared Nextcloud or a small website, is all that's needed in many cases.
For this I even use a little Raspberry Pi 400 in my bedroom.
https://joeldare.com/private-analtyics-and-my-raspberry-pi-4...
I’ve self hosted my own stuff for close to a decade now. Nobody has tried DDoSing my setup, because why would they? What benefit would they possibly get out of it? I would be pretty much the only person affected, and once they stop it wouldn’t take long to recover.
There is little to no incentive to DDoS a personal box, let alone by a “internet rando”.
You are drastically overestimating a teen's abilities.
Just pinging the IP over and over again isn't really going to do much. Maybe a DoS attack depending on what the target network has in terms of IPS, but even then it's more likely they'll infect their computers with viruses before they get the chance to actually attack you.
I've personally been on the receiving end of one of those for somehow pissing off a cheater in GTA 5. It definitely happens and it's not fun.
Edit: It looks like this might be automatic. This is something interesting I should look into a bit. It’s probably just extra complexity for my little server, but I’ve got some uses in mind.
Tehcnically my homelab is also on a static public IP as well--this was more an exercise in "could I do this" than "actually necessary," but it's still cool as hell and I'm very happy.
About the only hangup was I had to configure Wireguard to keep the tunnel alive, otherwise sometimes the VPS would receive incoming traffic and if my lab hadn't reached out in a while (which, why would it?) the tunnel would be down, and the proxy connection would die. Thankfully that's built-in functionality.
So, it seems like adding RSS / Atom feeds on a jekyll or GitHub pages site is pretty straightforward.
1. https://github.com/jekyll/jekyll-feed
2. https://docs.github.com/en/pages/setting-up-a-github-pages-s...
atom 2c/4t, 4gb ram, 1tb drive, 100mbit
A few years of uptime at this point
If uninterrupted: some upgrade may be due. ;-)
Kernel security updates are a thing.
---
I found Atoms to be unbearably slow, even with Linux. Of course it’s enough for serving websites and whatnot, but it’s baffling how much power they use just… not performing.
Exactly. These sub-$10 VPS instances are great for small projects where you don't want to enter into long contracts or deal with managing your own servers.
If you're running an actual business where margins are razor-thin and you've got all the free time in the world to handle server issues if (when) they come up, those ~$50 dedicated servers could be interesting to explore.
But if you're running an actual business, even a $10,000/month AWS bill is cheaper than hiring another skilled developer to help manage your dedicated servers.
This is what's generally missed in discussions about cloud costs on places like HN: Yes, cloud is expensive, but hiring even a single additional sysadmin/developer to help you manage custom infrastructure is incredibly expensive and much less flexible. That's why spending a hypothetical $5000/month on a cloud hosted solution that could, in theory, be custom-built on a $50/month server with enough time investment can still be a great deal. Engineers are expensive and time is limited.
Uhhh, excuse me but how much are you paying this DevOps guy? This seems like a very American perspective, even valley area. In Europe, hiring a guy would be cheaper.
I can hook you up in about 3 hours.
Fully loaded employment costs are significantly higher than what you take home in your paycheck. It's actually worse in Europe. Take a look at these charts: https://accace.com/the-true-cost-of-an-employee-in-europe/
If you pay someone 1000 EUR in the UK, it costs the company a total of 1245 EUR.
If you pay someone 1000 EUR in Romania, it costs the company 1747 EUR total.
So a $120,000 fully loaded cost might only buy you at $68,000 USD salary for an EU devops person.
But you can't have just one devops person. You need at least 2 if you want to allow one of them to ever take a break, get sick, or go on vacation.
Whatever you create, will start with 0 users, and an entire real machine is completely overkill for that 0 load you will get. You upgrade your VPS into a pair of real machines, then into a small rented cluster, and then into a datacenter (if somebody doesn't undercut that one). All of those have predictable bills and top performance for their price.
Anything you own in a colo is going to be more per month too. When I had connections where I could pay for a static IP, that was usually $5/month.
I'm now renting a pretty low end server, but it's $30/month. Way more everything that I need, but it's nice. And they didn't drop support for my OS while increasing prices to improve support or something. (Although I did have some initially flakey hardware that needed to get swapped)
Like you, I also run my services from a rented physical server. I used to use Versaweb, but their machines are too old. I didn't previously like Hetzner because I'd heard bad things about them interfering with what you're running. However, I moved to them in December when my Versaweb instance just died, probably SSD from old age. I'm now paying 50% of what I paid Versaweb, and I can run 6 such Postgres instances.
Then it makes one wonder whether it's worth paying $700 of $800 for a managed service with a fancy cloud UI, automatic upgrades and backups, etc. For a 1 person show or small startup, I think not. Cheaper to use an available service and dump backups to S3 or something cheaper.
There is an implicit cost there. If its only one or two of those things, just take the managed services.
If you start to scale, get an administrator type of employee to save on this
Company I used to work for happily paid company A four times what company B charged for the exact same service, just because company A was willing to send quarterly invoices in way that played nicely with our invoicing system. For companies, saving a few hundred bucks here and there often isn't worth the hassles of introducing any extra friction.
Otherwise, I'd have to hire/contract someone very experienced, or dedicate a solid month or more of my time (which was not available), just to be 100% sure we could always restore journaled PITR backups quickly.
I can save orders of magnitude on cloud costs other places, but credible managed PostgreSQL was a pretty easy call (even if the entry-level price tag was more than you'd expect).
An early startup that cannot afford to lose an hour of production data is probably too fragile to survive anyway.
It's an early startup - there's going to be larger interruptions than that to the service and any customers who flee after a one hour loss of production data just didn't value the product enough anyway.
(In the specific startup I was thinking of, I already had some nice automated frequent DB-online dumps to S3 with retention enforced, but I didn't think that was good enough for this particular scenario. But not being sure we coudl recover with PITR/journaling would adding a new single point of failure gamble on the success of a business that otherwise might have a 9+ figure exit in a few/several years, just to save a few hundred.)
Also, I suppose that some of the early startups that have less demanding needs, but are cavalier about their obligations towards customers'/users' data, are still being negligent wrt minimum basic practices.
Maybe one intuitive way to appreciate: Imagine a biz news story on HN, on some startup operations dropping of the ball, with startup founders' names attached, and the story says "...and it turns out they didn't have good backups...". Then one of the cofounders, who's maybe not slept much as their company is crashing around them, responds "Customer data isn't that important in an early startup; if it were, we'd be too fragile" (typed before the cofounder could throw that person's laptop across the room to stop them typing). It wouldn't be a good look.
I'll address this at the end.
> Imagine a biz news story on HN, on some startup operations dropping of the ball, with startup founders' names attached, and the story says "...and it turns out they didn't have good backups...".
ITYM "...and it turns out they didn't have the last hour backed up..."
I can imagine everything in your scenario, even the unsnipped bits, and it all seems normal, unless you read "Our startup clients, who've been using us for a month, all left immediately when we lost the last hour of their data".
I really can't imagine that scenario.
Now, granted, there are some businesses where the benefit to using it is that there is not even an hour of lost data.
IOW, customers use it because it won't lose any data: online document collaboration[1], for example[2]. If you have a meltdown that loses an hour of the last inputted data, then sure, expect all affected current users to flee immediately.
[1] Although, personally, I'd mitigate the risk by duplicating the current document in localstorage while it is being edited.
[2] Maybe stock exchange also needs the system to keep the last hour of data? What else?
I think even for larger teams it may make sense to manage databases yourself, assuming you have the competence to do it well. There are so many things that can go wrong with managed services and they don’t hide the underlying implementation the way that things like block storage or object storage do.
The main issue in any scenario involving real hardware is that you need staff who are competent in both hardware and Linux/UNIX systems. Many claim to be on their resumes and then cannot perform once on the job (in my experience anyway). In my opinion, one of the major reasons for the explosion of the cloud world was precisely the difficulty in building and the financial cost of building such teams. Additionally, there is a somewhat natural (and necessary) friction between application developers and systems folks. The systems folks should always pushing back and arguing for more security, more process, and fewer deployments. The dev team should always be arguing for more flexibility, more releases, and less process. Good management should then strike the middle path between the two. Unfortunately, incompetent managers have often just decided to get rid of systems people and move things into AWS land.
Finally, I would just note that cloud architecture is bad for the planet as it requires over-provisioning by cloud providers, and it requires more computer power overall due to the many layers of abstraction. While anyone project is responsible for little of this waste, the entire global cloud as an aggregate is very wasteful. This bothers me and obviously likely factors as an emotional bias in my views (so large amounts of salt for all of the above).
The argument could be made you can develop a means to to rent physical servers pre-income, then, when it makes sense, you can either use standard depreciation -or- Section 179 on outright purchases and/or Section 179 leases.
As an example, you can deploy an incredibly capable group of let's say four absolutely ridiculous completely over-provisioned $100k physical 1U machines in different colo facilities for redundancy. There are all kinds of tricks here for load balancing and failover with XYZ cloud service, DNS, anycast, whatever you want. You can go with various colo facilities that operate datacenters around the world, ship the hardware from the vendor to them, then provision them with Ansible or whatever you're into without ever seeing the facility or touching hardware.
So now you have redundant physical hardware that will absolutely run circles around most cloud providers (especially for I/O), fixed costs like all you can eat bandwidth (that doesn't have the 800% markup of cloud services, etc) - no more waiting for the inevitable $50k cloud bill or trying to track down (in a panic) what caused you to exceed your configured cloud budget in a day instead of a month. Oh btw, you're not locking yourself into the goofy proprietary APIs to provision and even utilize services other than virtual machines offered by $BIGCLOUD.
If you're doing any ML you can train on your own hardware or (or the occasional cloud) and run inference 24/7 with things like the NVIDIA A10. Continuous cloud rental for GPU instances is unbelievably expensive and the ROI on purchasing the hardware is typically in the range of a few months (or way ahead almost immediately with Section 179). As an example, I recently did a benchmark with the Nvidia A10 for a model we're serving and it can do over 700 inference requests/s in FP32 with under 10ms latency. With a single A10 per chassis across four healthy instances that's 2800 req/s (and could probably be tuned further).
Then, if you get REALLY big, you can start getting cabinets and beyond. In terms of hardware failures as mentioned, all I can say is dual PS RAID-ed out, etc hardware is (in my experience) extremely reliable. Frankly having had multiple full cabinets of hardware in the past hardware failures were few and far between and hardware vendors will include incredibles SLAs for replacement. You notify them of the failure, they send a tech in < eight hours directly to the colo facility and replace the disk, PS, etc with the flashing light.
My experience is one (good) FTE resource can easily manage this up to multiple cabinet scale. To your point, the current issue is many of these people have been snatched up by the big cloud providers and replaced (in the market) with resources that can navigate the borderline ridiculousness that is using dozens (if not more) products/services from $BIGCLOUD.
I've also found this configuration is actually MUCH more reliable than most $BIGCLOUD. No more wondering what's going on with a $BIGCLOUD outage that they won't even acknowledge (and that you have absolutely no control over). Coming from a background in telecom and healthcare it's completely wild to me how uptime has actually gotten much worse with cloud providers. Usually you can just tell customers "oh the internet is having problems today" because they'll probably be seeing headlines about it but for many applications that's just totally unacceptable - and we should expect better.
I've seen lots of less experienced people overpay for hetzner and similar when a $5-10 vps would've worked.
Keep backups in any case. Preferably on another provider or at least in a different physical location. And, of course, test them.
And if you are managing a good backup regime, and monitoring your data/app anyway, is monitoring drives a significant extra hardship?
-- [1] in fact if you automate the restore process to another location, which I do for a couple of my bits, then you can just hit that button and update DNS when complete, and maybe allocate a bit more RAM+cores (my test mirrors are smaller than the live VMs as they don't need to serve real use patterns).
as you pointed out, bare metal is the way to go. is works the opposite of cloud - a bit more work at the beginning but a way lot less of expenses at the end.
Even if I did want to update, it's just a case of pulling the latest version into the docker-compose template and re-running the ansible playbook. Obviously if the upgrade requires more then so be it, but it's no different to any other setup work wise.
Probably the only thing I _need_ to do which I do manually is test my backups. But I have a script for each project which does it so I just SSH on, run the one-liner, check the result and it's done. I do that roughly once a month or so, but I also get emails if a backup fails.
So it can be no time at all. Usually it's probably 1-2 hours a month if I'm taking updates on a semi-regular basis. But that will scale with the more things you host and manage.
In other words, the only difference is where the ansible inventory file comes from. Either it's a static list of IPs, or it comes from terraform.
If I want to spin up a new project or try out hosting something new it takes a couple minutes and I've got the scripts. Deployments are fast, maintenance is low, and I have far more for my money.
For anyone who's interested this is the rough cut of what I'm using: * Ansible to manage everything * A tiny bit of terraform for some DNS entries which I may replace one day * restic for backups, again controlled by ansible * tailscale for vpn (I have some pi's running at home, nothing major but tailscale makes it easy and secure) * docker-compose for pretty much everything else
Main app is Clojure, so I run a native JVM. Database is fully distributed, RethinkDB, now working on moving to FoundationDB.
The important thing is not to manage anything manually, e.g. treat physical servers just like any other cloud server. It shouldn't matter whether it's physical or virtualized.
I used a VPS before that, but stopped and switched to a physical one because it was a better deal and we didn't run into CPU limit(ation)s.
I was more of a junior dev at the time so maybe I was an idiot, but I don't miss it at all. In theory I agree with what you're saying, but deploying a Dockerfile to something like Google Cloud Run is just a hell of a lot easier. Yea I'm paying more than what I would be managing my own VPS, but I think this is more than offset by the dev hours saved.
My employer adopted cloud as a business/financial play, not a religious one. We often land new builds in the cloud and migrate to a data center if appropriate later.
The apps on-prem cost about 40% less. Apps that are more cost effective in cloud stay there.
Hetzner has an API for ordering dedicated servers after all, and an API for installing an OS (or for rebooting to rescue and flashing whatever image you want)
for the same spec, sure. I think virtuals make sense at both ends - either dynamic scalability for large N is important, or you only actually need a small fraction of a physical box. Paying 45/mo for something that runs find on 5/mo isn't sensible either, and gives you more flexibility for not ganging things together just to use your server.
Exactly what I do for myself and my clients. Saves tons of dosh.
1. Forces config to be reproducible, as VMs will go down.
2. You can get heavy discounts on AWS that reduce the pain.
3. The other stuff you have access to atop the VMs that's cheaper/faster once your stuff is already in the cloud
4. Easier to have a documented system config (e.g. AWS docs) than train people/document what special stuff you have in-house. Especially useful in hiring new folks.
5. You don't need space or redundant power/internet/etc on premesis. Just enough to let people run their laptops.
I think it's the case that AWS/GCP/Azure are not very cost-competitive offerings in Europe. What I'm not seeing is evidence of that for the US.
Yes, you're supporting your own hardware at that point. No, it's not a huge headache.
- physical hardware has trouble, e.g. fan failure -> my VM gets live migrated to a different host, I don't notice or care
- physical hardware explodes -> my VM restarts on a different host, I might notice but I don't care
Disaster planning is a lot easier with VMs (even with pets not cattle).
Sure it's only an ATOM N2800 with 4 GB of RAM / 1 TB SSD / 100 Mbit/s bandwith (which is definitely the bottleneck as I've got gigabit fiber to the home).
But it's 5 EUR / month for a dedicated server (and it's got free OVH DDoS protection too as they offer it on every single one of their servers).
I set up SSH login on these using FIDO/U2F security key only (no password, no software public/private keys: I only allow physical security key logins). I only allow SSH in from the CIDR blocks of the ISPs I know I'll only ever reasonably be login from and just DROP all other incoming traffic to the SSH port. This keeps the logs pristine.
Nice little pet these are.
I'm not recommending these 5 EUR / month servers for production systems but they're quite capable compared to their price.
Where?
I had to wait a few days to fetch my last one but I got it. Always do : )
On OVH's website: OVH cloud / Bare metal & VPS / ECO Dedicated Servers.
P.S: back in the days the "Kimsufi" (french for "qui me suffit", literally "which is enough (for me)") used to be part of OVH, then OVH spun Kimsufi out of OVH and then now... Kimsufi are back into OVH (the older Kimsufi servers are still accessed using the old Kimsufi credentials but the newer ones are using the OVH credentials again).
Surely, "qui me suffit".
https://eco.ovhcloud.com/fr/compare/
But then when you click on the link you'll see the 4.99 offering and then after a split-second it's removed (because none are available atm).
But really: with some patience anybody can fetch one. Or you "cheat" and you use a script to see when they're available.
In my experience they're easier to fetch "when Europe sleeps" (so, say, at around 3am in France).
Just a small gotcha for anyone considering migrating off another platform: I only realized after purchase the 100Mbps advertised network bandwidth, versus a $5 Lightsail's advertised ~400-500 that I'm moving over from.
The OVH machine I ordered seems to be less smooth, and I'm simply running into issues. I am performing the same exact steps as I do on a 0.5 GB Lightsail instance, where it works just fine. My workloads just aren't working on OVH. I have run out of patience and am going to cancel and stay with Lightsail.
Works really well, highly recommend it. I don't block traffic from anywhere since I travel a lot. It's interesting to open the nginx logs and see all the automated scans checking me out.
I'd think they are fit for production, a few services use them, like Lichess (can see their stack here https://lichess.org/costs )
I just meant that I wouldn't recommend the 5 EUR / month dedicated servers for production: these do not have a big bandwidth and they don't have ECC RAM.
I edited my other post accordingly.
the very good DDoS protection just seems to null route YOUR ip if it receives more than a certain amount of traffic/second
for me it used to trigger a few times a year from just random internet noise, like a portscan (as no-one other than me knew the host even existed)
This is not how it works. I recommend you go to the related webpages (just type "OVH antiddos" on Google), the anti-DDoS system is well documented nowadays.
If you _actually_ suffer from "null-routing"-like issues when the anti-DDoS triggers, you might want to get in touch with the support team to escalate the issue.
I have a feeling they may be very interested about this.
Seeing their single greatest cost line-item being "site moderation" (more than developer salary!) is such a stark reminder of where the real problems running an internet service are.
The other argument would be paid for services tend to be setup with the expectation that the price will increase ( inflation for instance ). Where as an always free gives the expectation that it'll always be free and as such a user might specifically design their system to stay within that limit.
This is a new thing as of last week, I think.
Also, Oracle Cloud's management interface is best described as "let's make this as complicated as AWS, but with more 'Enterprise-y' features, but somehow worse in every possible way."
That said, I can't fault Oracle for being Oracle. I knew what I was getting myself into. And their "Always Free" tier is still free. And it does work well enough for my purposes.
Reclamation of Idle Compute Instances
Idle Always Free compute instances may be reclaimed by Oracle. Oracle will deem virtual machine and bare metal compute instances as idle if, during a 7-day period, the following are true:
* CPU utilization for the 95th percentile is less than 10%
* Network utilization is less than 10%
* Memory utilization is less than 10% (applies to A1 shapes only)
https://docs.oracle.com/en-us/iaas/Content/FreeTier/freetier...edit:
stress --vm-bytes $(awk '/MemAvailable/{printf "%d\n", $2 \* 0.12;}' < /proc/meminfo)k --vm-keep -m 1
And limit CPU use using cpulimit. ORPort 9001
Nickname foobar
AccountingMax 512 GB
AccountingStart week 1 00:00
DirPort 9030
ExitPolicy reject *:*
They give you 10 TiB of data transfer per month, this will make sure tor never goes above 4 TiB tops.I guess even Oracle is staring down the barrel of IPv4 infertility.
They're pretty much worthless. That atom processor hasn't even got support for AES-NI, meaning that all crypto must be done without hardware acceleration.
Basically all traffic (https? ssh? sftp? vpn?) is heavy duty for that procesor for the sole reason of existing.
I can literally see a cpu 100% busy because i'm downloading a file over sftp in another terminal.
Unless you're doing stuff in cleartext, which restricts the acceptable use cases by a lot.
Really, that kind of servers are really toys.
Also, in case of problems the datacenter people will just shut it off, replace it and re-provision it. I had the (single) disk fail on my kimsufi and the OVH people replaced it and rebooted my server to a blank state.
Ok fine, thank you and everything but where did my data go? Who's been handling my data on the PHYSICAL disk?
Really, those servers are barely toys.
Don't get me wrong though: great toys, but TOYS.
Was a customer for years, and one day they said my server had died and gave some excuse that there was no way to physically access the hard drive as it was in a rack of other servers or something along those lines.
So what happens to my data? It can't be recovered but when is it going to be securely destroyed?
They’re cheap and “infinitely scalable.” I originally picked them for my CRUD API because I didn’t want to have to worry about scaling. I’ve built/managed an internal serverless platform at FAANG and, after seeing inside the sausage factory, I just wanted to focus on product this time around.
But I’ve noticed something interesting/awesome about my change in searches while working on product. I no longer search for things like “securely configuring ssh,” “setting up a bastion,” “securing a Postgres deployment,” or “2022 NGinx SSL configuration” - an entire class of sysadmin and security problems just go away when picking workers with D1. I sleep better knowing my security and operations footprint is reduced and straightforward to reason about. I can use all those extra cycles to focus on building.
I can’t see the ROI of managing a full Linux stack on an R620 plugged into a server rack vs. Workers when you factor in the cost of engineering time to maintain the former.
I do think this is a new world though. AWS doesn’t compare. I’d pick my R620s plugged into a server rack over giving AWS my credit card any day. AWS architectures are easy to bloat and get expensive fast - both in engineering cost and bills.
Like GP, I'm also using D1 (https://developers.cloudflare.com/d1) which is based on SQLite and still in early Alpha. In combination with KV (https://developers.cloudflare.com/workers/learning/how-kv-wo...) it's trivial to have a great database layer with caching using kysely (https://github.com/aidenwallis/kysely-d1) and trpc (https://trpc.io) you can have typing from DB to front end.
./sql/0001_create_users.sql
./sql/0002_create_sessions.sql
....
Each query for modifying the schema is idempotent and safe to be rerun.Then I do:
ls ./sql | xargs -I{} wrangler d1 execute <db> --file {}
Can put that in a script to make things easy. You use the same script to modify the db as you do to bootstrap a db from scratch.Just buy a domain name and start deploying. Unlike other cloud providers (looking at you Azure/AWS) the time from push to deployment finished is under a minute. Azure could take 15-20 minutes and AWS still relied on zip file uploads for functions last I checked.
Most code I’ve rolled on Workers is simple because it’s just business logic (the OS takes care most of the heavy lifting that adds bloat to other code bases). Migrating a few 1000 lines of JS isn’t a big deal. I just don’t have very many places I could move it to.
Lambda is region bound. I could do lambda@edge which is closer. But self hosting it on an R620? I could probably roll an API compatible wrapper that loads my worker into a node process on a standard server and plug it into a colo rack, would take me a few hours, but that’s not comparable.
This idea of self hosting and building portable abstractions I feel is jumping the gun. We are just starting to figure out how to build operating systems for datacenter scale computers, but standardization is still a ways out there. Planet scale is a whole ‘nother level, and we’ve got a long ways to go to figure out what the right abstractions are for computers of this scale.
If you depend on them for everything and then they decide to make a big price increase to become profitable. Will you be able to handle that price increase? You are pretty much stuck with paying the price.
Yeah other companies can increase their prices, but most of the time profitable companies in cloud infrastructure will only increase if their expenses increase and this is pretty predictable if you pay attention to costs. Like last year it was pretty easy to predict a price increase coming because of inflation and supply chain issues.
I'm nervous about them changing their pricing too, but just the fact that they're so much more transparent than AWS or GCE is a net plus for me, even with an increase in price.
[0]https://simplywall.st/stocks/us/software/nyse-net/cloudflare...
(ignore the contents and forecast of the article and just look at the graph)
It’s also worth noting the development patterns they force when building on Workers and Pages sends you down the path of a fairly portable architecture.
I can’t say anything I’m doing would be difficult to port to another provider on short notice.
The question I ask first is: as a company, what is an acceptable downtime per year?
I give some napkin calculated figures for 95%, 99%, 99.9% and 99.99% to show how both cost and complexity can skyrocket when chasing 9s.
They soon realise that a pair of live/standby servers might be more than suitable for their business needs at that particular time (and for the foreseeable future).
There is an untapped market of clients moving _away_ from the cloud.
A) Customers actually chase the credit, which (again IME) many companies make very difficult
B) The downtime is very clearly complete downtime. I've seen instances where a mobile app is completely down (but the web product works) or a key API is down (but the core product works) or there are delays in processing data (but eventually things are coming through). All of these can cause downstream downtime to customers but may not be covered by a "downtime" SLA.
I've worked at one of those companies that have the live/standby model in place.
The problem is, how to switch load from live to stand-by in case of problem often requires manual intervention and a procedure.
The procedure must be tested from time to time, and adjusted according to changes.
Oh and the live and standby environments must be kept in sync...
Also, we have seen both cloud and non-cloud hosts having significant downtime more than their SLA but just put it down to a "small subset of our customers" so they don't have to do anything.
It's a bit like my Student Loan guarantee, "Do the paperwork and we guarantee you will have the loan on time". The loan was not paid, "I thought you guaranteed it?" "We do but we made a mistake" "So what do I get because of the guarantee?" "Nothing". Cheers!
Vultr’s, as an example I’m familiar with, being a customer, but which I believe is pretty typical:
• 100% uptime, except for up to ten minutes’ downtime (per event) with 24 hours’ notice or if they decide there was a time-critical patch or update. (I have one VPS with Vultr, and got notice of possible outages—identified purely by searching “vultr service alert” in my email—8× in 2022, 3× in 2021, 14× in 2020, 9× in 2019. No idea how many of them led to actual outage.)
• They’ll give you credits according to a particular schedule, 24–144× as much as the outage time (capped at a month’s worth after a 7h outage, which is actually considerably better than most SLAs I’ve ever read). Never mind the fact that if you’re running business on this and actually depending on the SLA, you’re probably losing a lot more than what you’re going to get credited for.
• Onus of reporting outages and requesting credits is on you, by submitting a support ticket manually and explicitly requesting credit. So the vast majority of SLA breaches (>99.9%, I expect; I don’t care to speculate how many more nines could be added) will never actually be compensated. And determination of whether an eligible outage occurred is at their sole discretion, so that they could frankly get away with denying everything all the time if they wanted to.
Such SLAs basically just completely lack fangs. I suppose you’d want something along the lines of insurance instead of an SLA, if it all mattered to you.
I've never had any performance issues. A $5 VPS is plenty for Apache, PHP, PostgreSQL, for a few thousand users a day.
I've started using multiple VPS, one for each service. Not for performance reasons, but for two things:
- isolation: if there's a problem with one service (eg. logs used up all disk space) it doesn't bring everything down at once
- maintainability: it's easier to upgrade services one by one than all at once
How you develop an application depends completely on what you have available to you and what its use case is. If you don't have money, design it to be resource-efficient. If you do have money, design it to be a resource pig. If it needs to be high performance, design it to be very efficient. If it doesn't need to be high performance, just slap something together.
As a developer, you should know how to design highly efficient apps, and highly performant apps, and how to develop quick and dirty, and how to design for scalability, depending on the situation. It's like being a construction worker: you're going to work on very different kinds of buildings in your career, so learn different techniques when you can.
I highly recommend, for fun, trying to develop some apps inside a VM with very limited resources. It's pretty neat to discover what the bottlenecks are and how to get around them. You may even learn more about networking, file i/o, virtual memory allocation, CoW, threading, etc. (I wouldn't use a container to start, as there's hidden performance issues that may be distraction)
If you expect any comprehensive benchmarks or testing, save the time.
Anyone in this industry is prone to these absolutist ideologies. I wasted a half-decade chasing perfection myself. In reality, there are very few real world systems that cannot go down. One example of a "cannot fail" I'd provide is debit & credit processing networks. The DoD operates most of the other examples.
The most skilled developer will look at a 100% uptime guarantee, laugh for a few moments, and then spin up an email to the customer in hopes of better understanding the nature of their business. We've been able to negotiate a substantially smaller operational footprint with all of our customers by being realistic with the nature and impact of failure.
If you can negotiate to operate your product on a single VM (ideally with the database being hosted on the same box), then you should absolutely do this and take the win. Even if you think you'll have to rewrite due to scale in the future, this will get you to the future.
Periodic, crash-consistent snapshots of block storage devices is a completely valid backup option. Many times it is perfectly OK to lose data. In most cases, you will need to reach a small compromise with the business owner where you develop an actual product feature to compensate for failure modes. An example of this for us would be emailing of important items to a special mailbox for recovery from a back-office perspective. The amount of time it took to develop this small product feature is not even .01% of the amount of time it would have taken to develop a multi-cloud, explosion-proof product.
Someone had a site set up to measure VPS providers by running a suite of tests every hour and collecting the results by hosting provider. Was surprising to see transient performance degradations, downtimes and stark differences in performance for "2 vcpu 1gb ram" depending on the hardware underneath and level of overprovisioning.
Edit: the aptly named https://www.vpsbenchmarks.com/screener
Like OVH - if you need support for anything beyond provisioning/troubleshooting things outside of the VM, it's not the best choice.
If you compare it with ec2 support costs + vm costs... it's difficult to have it all.
Digital Ocean does a good job of support too, but I'd rather not need support (with most tooling self-serve) than have support but have issues. I've had VMs at vultr running for 3+ years with very few issues (one host migration which they did "live" for me and notified me a few days in advance). I've had more issues with degraded instances in ec2 that require a ticket sent to ec2 support and 3-days wait for them to assign it to a new host.
I'll counter that. I found that their customer service was acceptable as far as I could tell. I ran an OpenBSD bare metal server on them for quite a while.
Were they great? No. But I have also found that the big guys aren't that great either. Sure, the big buys hit a lot more problems so it's likely your issue is resolved because somebody big paying lots of money also just had that problem.
However, if your problem is semi-unique and some large customer isn't also having it, you are completely SOL with the big providers. They will never fix your issue.
They did give me my money back when I asked.
They changed the pricing out under me and make it difficult to migrate out. At the time there was a very restrictive upload bandwidth so it would have taken weeks to upload my database backup files to the new hetzner servers. We ended up putting effort into finding the core data which can't be lost and only uploading those individual tables/row filters.
IDK how they are now but for sure go check upload limits.
And that was not shown anywhere before the signup.
So yeah, i'm downvoting for scaleway too.
From there I would export those metrics to a grafana+influxdb setup. But honestly this is because that's what I'm used to professionally. There might be simpler solutions around.
I could use one for things like remote cronjobs.
How much is the service of cron-job.org?
Our service is entirely free of charge.
( Some resource limits apply )https://my.frantech.ca/aff.php?aff=3460
This is the parent company of BuyVM. They have a very good reputation, but their stock goes up and down throughout the month. If you want a specific data-center location, wait until the first of the month when stock replenishes.
$1/month list: https://lowendbox.com/blog/1-vps-1-usd-vps-per-month
I think you'll still find deals like this on lowendbox occasionally.
Original deal: https://lowendbox.com/blog/cyber-monday-virmach-vps-deals-as...
Disclaimer: I work there
Keep the boxes up-to-date with "unattended-upgrades" or similar.
And reboot your servers regularly.
I do agree that there are some core services that I don't want changing out from under me without my notice/prior testing. But then there's also a lot of stuff installed that I don't use directly (eg OpenSSH) in my application and I'm not sure if those are attack vectors.
Setup unattended upgrades for your distro of choice, setup fail2ban, only make internet accessible the ports you need, upgrade out of date software (i.e., don't fall behind LTS). Make sure your software behaves with good security practices (don't trust user input, etc). Any modern guide these days should just about cover it.
For more complex deployments you'll enter the world of reverse proxies, custom VLANs, automation abstraction, intrusion detection systems (i.e., applications that proactively monitor access logs for suspicious activity), logging systems, alerting systems...
But for simple app deployments, getting a reasonably secure system setup is actually not that hard. Maintaining it and keeping it secure is another matter (keep private keys secret, don't use simple passwords for SSH, etc), dealing with large upgrades, don't deploy debug to prod...
A bit cheeky, but to highlight the point: you just locked yourself out of SSH.
So that just leaves keeping things uptodate, which is easy by subscribing to your distro's security mailing list, and updating when something relevant comes up. Which is rarely on a simple webhost VM.
For network, again, your required services should be somewhat easily definable for inbound unless you're hosting multimedia/UDP/P2P services. This is the basics... for enterprise level stuff you get into application-aware firewalls, IPS, and WAF.
These days I’m running my static site builder, a few scrapers/RSS converters and a number of Mastodon-related services on it, on various kinds of cloud and physical hardware…
Had one of those when I was a broke student, and found that on lowendtalk.com as you suggest.
Needless to say, the company literally VANISHED after a few months.
If an offer is too good to be true...
In this case, there are max 50 workers hitting the server, so you’d expect 50 parallel requests to be outstanding at once. 1300 req/sec with 50 workers, would be 26 msec/req, which matched the results.
So I wonder why the server being pegged didn’t affect things more? Super curious what the server side metrics were during the test.
Constant Load, which k6 supports, can help pinpoint the server’s breaking point.
Hetzner Cloud allocates you 20TB per VPS (yes, even the cheap ones) and lets you use that however you see fit. There have been about 2 known instances of Hetzner kicking off dedicated (not VPS) customers for traffic abuse, and those customers were saturating the link 24/7 and were offered dedicated lines ahead of time. (their actual pain limit seems to be averaging over 750Mbit/s for 2-3 months). Their network team gets very upset if you scan from the instances, but not usually to keep a single limited interface from being saturated.
Netcup will throttle you 100 Mbit if you exceed 80 TB a month. Even on their 3,25 EUR VPS product.
And you can do a LOT using such VMs, now that most are hosted on SSDs instead of spinning disks.
My take-away points are the following:
1) Beware of cheap OpenVZ offers (e.g. on LEB or WHT), performance is usually worse than offers with proper virtualization like KVM, and the need to patch OpenVZ into the kernel causes most offerings to use a more or less outdated Linux Kernel leading to a very questionable level of security.
2) If your VM hosts "serious" data, you should better make sure to do your research and use a reputable hosting provider. This may potentially cost a bit more but will save you a lot of headache in the future.
3) Unless it's just a toy project, you should look into enabling replication of your data across two or three different VPS providers. While this at most triples your performance, the reliability will increase at least tenfold.
I'd have thought even LXC would have universally taken over by now. Who is still running CentOS 6 as a host?
I think OpenVZ has kernel patches for RHEL7's 3.10.x kernel, which is supported by Red Hat till 2024. So in theory it's possible to have a secure OpenVZ VM but in reality bad practices (like heavy overselling the hardware) flock together.
But a ~$10 virtual box with 2GB of RAM works fine. Nothing to complain. I get 2TB transfer and 50 GB space.
Enabling swap during the update sounds like an elegant solution.
It’s for packagekit, which is known to suck in this way.
A `systemctl restart packagekit` right after the update will immediately drop it below 30MB.
I want to do this:
- image some hardware with Ubuntu
- set up SSH
- write a definition file, HCL is fine
- run a program that uses the definition and the IP address of the machine that applies the definition installing files, programs, whatever or removing them
It would be cool if:
1. There were a terraform provider for this
2. I can specify which IP address the hardware is at
3. `terraform apply` and be done with it
The cloud is absolutely fantastic for lots of things, and we have a mix of cloud infra and on-prem hardware. Ideally, I'm looking for something a 4-person team can manage with some wiggle room for failure. If we hit 99.9 we're fine, maybe even get by with 99.
After all, the alternative is that I reimage one of the servers on the few racks we have and it takes precious time but it's not really a problem.
I mainly use puppet to manage my hobby machines & VMs, and puppet does violate the agentless bit you mentioned. What I like about it (over something like Ansible) is that it understands the resource dependency tree like Terraform does. Furthermore, I've set up my implementation so that it restores backups after installing services. So, for me, rebuilding a server is simply running a backup (optional) and then wiping the box.
I saw a libvirt provider for terraform recently that can SSH to a host and then operate the libvirt API on it. That seems like a good starting point for something like this; take the SSH parts and use it to manage resources like files on the remote host.
I've written a few simple terraform providers, it's not that hard to do. This sounds like a fun project and I'm pretty tempted to do this, actually.
With gigabit symmetric fiber connection (that I paid for) I don't see why I need to host stuff on other people's infrastructure. I can control backup in person.
I don't need to worry about the hoster upgrade a SAS controller and boink the RAID-ed hard drive, or complaints about copyright materials etc, or the hoster snooping on the servers for sensitive data, or that the hoster suddenly go out of business and take all my data with it, or that I reach the monthly 1000TB limit.
My parents even get to use gigabit connection for free so it's a win-win.
K6s is a pretty good load testing tool, however my problem with it is that it doesn't simulate everything a browser does: fetching all of the image files, fonts, as well as anything that might get downloaded and executed after upgrading the version of your application with some new functionality, but forgetting about adding new API routes etc. to the tests (e.g. if a new panel in the app gets loaded even without explicit user input, say, a new UI improvement with some useful data). You might need to do updates to your test code with each next app version for this, a relatively high maintenance approach.
The way I've worked around this previously was setting up Selenium + Python inside of containers that were assigned system users through a centralized service I wrote for that and then used the site in question like a real user would. It was pretty close to the real world, though sadly didn't scale too well - because with each automated browser instance needing ~512 MB of RAM, only small amounts of users could be viably tested.
Either way, small VPSes are still a great option in my eyes! Here's a few providers that I've personally found viable:
- Hetzner: https://www.hetzner.com/cloud (time based billing, good selection of services, also allows easily attaching more storage etc.)
- Contabo: https://contabo.com/en (pretty good option, the UI used to be a bit antiquated, there are setup fees, apparently a bit overprovisioned)
- Time4VPS: https://www.time4vps.com/?affid=5294 (I use them for my sites, affordable and stable, though not as modern as Hetzner; affiliate link, remove affid otherwise)
- Scaleway: https://www.scaleway.com/en/stardust-instances/ (overall expensive, but their Stardust offering is pretty good, when available, which isn't that often)
Apart from that, it can also be quite useful to take some old hardware and turn it into your own homelab - I'm currently doing that for my NAS, backup nodes and CI nodes, just a few AMD 200 GEs with 35 W TDP that are way cheaper than anything that actually needs good uptime. For example, buying a 1 or 2 TB HDD for storing data is cheaper than most cloud options, even when you include additional expenses for backups. As for compute, it varies - if you have workloads that need to infrequently do lots of number crunching, the cloud can be cheaper, actually.The smallest VPS are also the most unreliable in my experience. If that's a requirement of your low compute project, it may make sense to massively over provision with either a more expensive VPS or dedicated server. I'm not sure why but I suspect it's some combination of older server hardware being relegated to host lots of tiny VPS (which tend to host less uptime-critical things). Sharing the hardware between more VPS giving rise to more problems, e.g abuse, or over loading since they will be on average under-provisioned.
This is of course completely anecdotal, historical and speculation, some providers offerings may be just as stable at the bottom end. But it's certainly more likely at the bottom end.
But unless it's a simple static site it's usually not, and it's usually a source of a lot of complexity and pain. Which unless you really are doing something twitter scale, is not worth it.
By the time you've bought a handful of tiny VPSs and put in the work to horizontally scale your service, you could have put the same money with zero effort into a very reliable dedicated server. Spend the effort elsewhere and save your sanity (and probably improve your reliability).
Yes I'm biased against horizontal scaling.
At one point I was pretty steadily making $2000 a month revenue on my side business, sometimes peaking to $3000. Mostly serving up JSON (or XML at one point) as well as media like PNGs or epub's or the like.
The Linode has 4 gigs RAM, 2 CPU cores, 80 gigs storage, runs Debian. I'm given 4 TB of net traffic a month, but I never even got to 1 TB a month.
I did look at VPS's which were even cheaper at the time - less than $10 a month, but I passed on them, $400 a year for VPSs was within my allocated budget, especially since revenue was over $20,000 a year.
"web scale", but it's on a $4 VPS? What does that matter? I expect PG to do better.
I've been doing this for more than 10 years and I've been making incremental (sometimes really small) improvements to the way my web apps work so that I rarely need to go down to AWS, k8s, load balancer etc etc way.
Sure, these are personal projects and of course there is a diminishing return on optimizing (so I do upgrade hardware when I need to), but I always found it a rewarding challenge to first look at understanding the inherent issue, rather than just throwing money at it (at my work, it's completely opposite - see an issue? throw money and upgrade hardware ASAP and move on).
Some things I've done for optimizing are...
- Simple upgrading of software - going to latest postgres, upgrading PHP - Identifying data that are not frequently updated and then caching them - I've identified some bot traffics coming from China, so for one of my projects, I just blocked it completely (yeah, drastic I know, but not worth my $2!!)
There are also many many services out there that provide free tiers that you can utilize. So as a solo, indie dev, there are many ways to leverage to stay on a cheap $5 linode box as long as you need (I saw recently a box for $2.50 - tempting...)
The cheapest Ryzen with a RAM upgrade does get pretty close too, and at least that's a modern CPU.
You cannot get anything anywhere close to that in Azure, GCP, AWS, etc. for that price.
Where?
https://pebble.sourceforge.net/
But it was not so easy. Java refused to start with an out-of-memory error. It took me many hours to find out that the VPS had assigned very little memory at start. It was possible for the JVM to expand once running, but the initial request had to be small enough to avoid the error and not so small as to prevent Pebble from running.
Once this problem was fixed and iptables set, everything was fine. I even setup postmail. But the experience taught me that a VPS has different rules. I wouldn't trust the measurements in the article. They could depend on the load that other VPS in the same machine are supporting at the same time.
I run a web server with family photo albums that are all static pages.
My friends and I use it to exchange files.
I also use it as a SSH reverse tunnel relay to access my home machine from outside.
I don't really need to do anything else and it works well for that.
https://www.tensorflow.org/lite
https://huggingface.co/muhtasham/olm-bert-tiny-december-2022
https://neuml.hashnode.dev/train-a-language-model-from-scrat...
With the fed increasing rates, engineer salaries falling, and the market now valuing profit over sales, this is no longer true.
The companies that do not adapt to this reality will have subpar results.
That said, you shouldn't dismiss cheap hosting, I use a $4.5 VPS to constantly encode h.265 and it's been a great value.
The client was skeptical and asked about whether it's gonna be stable and scalable.
3 months later, the app is running buttery smooth.
I run my own OpenVPN, ssh, SMTP (postfix) and even http(s) and dav server.
I also have a wiki and an ftp server.
Most of the services are on the VPN private address space.
I honestly don't need to look for alternatives.
It's far more than enough.
How about some more robust testing that mimics real world scenarios?
My dream SAAS or cloud company is one that does payments and revenue to resource scaling. They integrate your payments solution of customers to scalability of your infrastructure.
In other words, the more active customers you have the more capacity you have. They would handle all the payments collection and take a cut of your revenue.
The guarantee is that you can handle any number of customers based on the number of paying customers.
Sound crazy? Same principle has worked since the 80s: the personal computer!
"A virtual private server (VPS) is a machine that hosts all the software and data required to run an application or website. It is called virtual because it only consumes a portion of the server's underlying physical resources which are managed by a third-party provider. However, you get access to your dedicated resources on that hardware."
(define on Amazon's website)
It sure does. Having to size for peaks and troughs, for when the updates are running, for when you get a spike in traffic, for when you need to use a slightly under-performing DB library or some connections to cache.
The only thing this small server would be any good for would be a static web site, pretending that any web app would work on a tiny vps is just not true.