Zero-Downtime Hetzner Deploys with Ansible
scratchdb.com
scratchdb.com
Hetzner has THE BEST UX for their cloud-vps stuff. Please don't change a thing, just for the sake of changing something. Looking at "YOU Spotify !" Compared to most of the other cloud vendors, its refreshingly simple and elegant ! Good job whoever did it, now the job is to KEEP it like that.
Happy customer for about 1.5 years now.
What's the blocker?
I just tried IPv6 and got 23.0 to 23.3 ms, so that's a pleasant suprise. Last time I checked IPv6 was higher latency. Unfortunately I don't have IPv6 at my office or at home so it's not worth using for my work.
From both my office and home, pings to my Hetzner servers are 50 to 85ms. That's because of the slow links I have locally.
Those times are not huge but all the little latencies add up when doing things interactively, especially those that take multiple round trips. You probably wouldn't want to run a game server with those latencies.
I found remote editing files with Emacs Tramp particularly slow at that latency because it does too many unnecessary round trips. For remote compiles I have an SSH session open and use Git or rsync to transfer files to/from my laptop, but that's annoyingly slow as well. I still use Hetzner servers for development because the compute hardware is much better than anything for a comparable price in the UK, but I would probably switch to a UK-located version if Hetzner opened a data center in the UK with similar hardware and pricing - which seems unlikely!
Anything you'd like us to improve in terms of UX or DX of our Open Source integrations?
Basically, I'm working on building the kind of company that I've always wanted to: simple technology (not k8s!) to do cool things (ingest tons of data into a database.) I can run the software on a single server, but my customers didn't want downtime when I deployed (who would've thought?) so I implemented a rolling deploy.
I've recently started hosting on Hetzner (ran out of AWS credits!) and have found the experience to be pretty good, and by far the best value of compute per dollar. If you don't want anything in the container world - I worked at huge companies that IPOed without containers - then consider their server offerings.
[1] https://www.haproxy.com/blog/dynamic-scaling-for-microservic...
I think if I were to do this I'd probably do it the other way around. I'd introduce the new code first on a new node, add it to the load balancer, check it's healthy, and then remove the old node.
It allows a bit more growth for new functionality should it be needed. For example you can run a canary for an hour and check the error rates before promoting the deployment. Or you can rollback if the new code fails to start for some reason without needing to reload the previous application version first.
On the other hand, this works great if you want to keep the VPS more long lived by recycling it.
You also make sure you get a clean VM each time configured the way your IaC dictates. Obviously if your nodes hosting the application are not under IaC or for some reason you want them to be long lived, then this doesn't work as well and your model is going to the better way to go.
As a result, I'm obviously very reluctant to believe the praise about them as I found this incredibly rude. There ought to be a better way to do this. I realize that this is only tangentially related to their technology, but still.
I really hope they can offer arm servers in the US.
When I reported it to the support, I was first told to visit the account login screen at the provided URL. To which I responded that, yes, that was what I was trying to do but could not reach. Next I was asked to reset my password; I did so, as that page is not protected by the same security challenge. Alas no change. Finally, it was suggested that I reset my router. Since it was the middle of the day with many other users on my network, I asked whether this was to see if IP blocking was in place. They said yes. Rebooting the router didn't change anything. I switched browsers, and it immediately worked.
So if anyone at Hetzner is listening, maybe have a look at your login protection and consider whether there is an alternative way to block bots (or whatever) without impacting legitimate customers.
Good to see tools and scripts around their offerings.
Hoping for that US DC at some point.
EDIT: Two, in Ashburn, Virginia, and Hillsboro, Oregon.
Well, live and learn I guess.