[1] https://www.statista.com/statistics/1338657/average-internet...
[1] https://www.statista.com/statistics/1338657/average-internet...
I also use a VPS for services intended for the general public.
Did they have CGNAT in 2003? Because that breaks everything.
Of course, IPv6 is its own can of worms, but (cross my fingers) it's working for me.
For me it broke online gaming. Luckily my ISP simply gives a static-ish IP to anyone who has an issue with CGNAT. But some ISPs force you to pay for a static IP, and some don’t even offer static IPs. I mean, I’d pay, but soon that won’t even be an option. It’s scary.
Even better if you have e.g. a Linode or any server with a public IP that can run Wireguard or OpenVPN. Then you can run your own VPN server, configure your DNS, and connect to anything from anywhere.
Yggdrasil (https://yggdrasil-network.github.io/) is also another interesting IPv6-based solution - I have played with it a bit, but I still prefer to use my VPN, and do nginx reverse proxy from my Linode to my network over VPN when needed.
I would also say that if you only want a static site the OPs setup is almost overkill. Just install caddy and a dyndns service. Takes care of the certificate for you and is super simple to setup.
Also, for those that don't know, Caddy also automates SSL certs (unlike nginx) and can render markdown files using templates [0].
[0]: https://caddyserver.com/docs/caddyfile/directives/templates
An ISP I've used in the past hasn't allowed self hosting on a standard plan but has allowed on a plan you need to ask for specifically.
In Taiwan I get 1gbps down, no caps, and a bunch of weird networky config stuff I don't quite understand but apparently you don't get in the usa, for like 30 usd/month. It's awesome.
Plus I'm torrenting basically 24/7 and my isp just doesn't give a fuck. When I did that in the usa Comcast sent me an email for every single torrent lol. My download is in the tens of terabytes a month and uploads are at least a terabyte a month. ISP doesn't care. Love it.
Web servers like Caddy automate this for you: you just indicate that you want HTTPS for a particular site and the rest is taken care of for you (in the case of public sites and HTTP-01 challenges, at least). Link: https://caddyserver.com/docs/quick-starts/https
Even Apache2 has mod_md which does pretty much the same thing (sans DNS-01 provider integrations, at least out of the box), so it's going to be good enough for most cases and similarly easy to Caddy. Link: https://httpd.apache.org/docs/2.4/mod/mod_md.html#mdomain
Nginx integrates well with certbot, which does take a bit more work and configuration, but even that is passable: https://certbot.eff.org/
Things can get a bit tricky when you want to run your own CA or ensure mTLS, but in most cases neither will be necessary.
As for whether you even need HTTPS in the first place, I'd say that it won't hurt in most cases and will guard against MitM, the ISP included.
example.com {
tls {
issuer acme {
disable_http_challenge
}
}
file_server
}
[0] https://caddyserver.com/docs/caddyfile/directives/tls#acmeMy ISP also put me behind CGNAT, which effectively meant that all of the inbound traffic got dropped. I worked around that by getting the cheapest VPSes that I could find and then setting up WireGuard and simply forwarding the traffic to my homelab servers. So I got all of the compute that I have available locally, all of the RAM and all of the cheap HDD storage, but a static IP address.
I actually wrote about the process a few years ago: https://blog.kronis.dev/tutorials/how-to-publicly-access-you...
(note that you probably would only want to forward 80 and 443 ports in most cases, not everything; outside of testing boxes)
Personally, I opted for Time4VPS in the end, which I use for the rest of my hosting as well: https://www.time4vps.com/linux-vps/?affid=5294#annually (affiliate link, they do have good discounts at the moment for yearly billing, though)
Then again, something like Scaleway Stardust instances could also be a really good fit, when they are available: https://www.scaleway.com/en/stardust-instances/
For those not chasing after the savings of a few Euros, Hetzner is also going to be more than enough: https://www.hetzner.com/cloud (or DigitalOcean, or Vultr, or any other VPS provider out there)
Also, if I have a VPS, why not just serve from the VPS?
Took me 15 minutes.
https://developers.cloudflare.com/cloudflare-one/connections...
Is it common for EU countries to not have symmetric gigabit fiber?
For example, at my last house (Melbourne), a 100/40 FTTC connection... the NBN company kept on having multi-hour outages (booked ahead of time) every 2-3 months. Note that's not my ISP, it's the NBN itself. For "upgrades" in the area and similar.
So very much "not business grade". Not even startup grade really. :(
Yup. I have a gigabit fibre right up to my home, but the best speed available to me as an individual is 400/40. Gets really annoying from time to time when I need to upload like a couple of gigabytes.
On the bright side it's like €30/month, which also gets me cable and some streaming service subscriptions (HBO Max, Tidal, shit like that), which from what I can tell is a pretty good deal compared to more western countries.
I'm in the US and have never not had something or other being served on public facing ports