Tech Independence
sive.rs
sive.rs
I'm passionate[1] about the concept but articles like this are a reminder to me that we need to make self hosting an order of magnitude simpler and accessible to more people. It shouldn't need to involve any CLI, DNS, TLS certs, port forwarding/NAT traversal, IP addresses, etc etc.
Self hosting shouldn't be any more difficult or less secure than installing an app on your phone. The flow should be 1) install the "self hosting app" on an old laptop or phone. 2) Go through a quick OAuth2 flow to connect your app to a tunnel that enables inbound traffic. 3) Use the self hosting app to install other apps like Jellyfin, Calendar, Nextcloud, etc. Everything should be sandboxed (containers work pretty well on Linux and Windows 10/11 via WSL2) and secure by default. Automatic backups (ideally an OAuth2 flow to your friends' self hosted installations) and auto app updates are table stakes.
There's no technical reason this can't all be done, but lots of technical challenges, and it's unclear whether anyone will pay for tunnels. I'm currently trying to figure out how to do reliable auto backups without filesystem snapshots.
[0]: https://youtu.be/0BaDQCjqUHU?si=0wDf-2RH-u9vdm3g&t=1380
We have to divorce society from these abusive corporate cloud relationships. It made sense 20 years ago. It is actively poisonous today.
We can easily make a turnkey opt-in peer to peer cloud using today's consumer grade open hardware and software, much of it default off the shelf.
I’d be keen to work on a project to marry a PaaS like Caprover with networking using ZeroTier or Tailscale, packaged in such a way that it could be easily deployed onto most reasonably equipped platforms, or delivered as a service.
People are really focused on privacy, and even opt-in integration with nonprivate hardware and services doesn't happen much.
Convenience features gtt completely ignored, and worst of all, a huge amount of P2P stuff has no mobile support.
Furthermore a lot of it involves a self hosted single point of failure. For me that's a complete deal breaker, it's not acceptable that a service could go down because something happened to a home server while I was away.
And then on top of that, most p2p projects for about 10 years were completely impractical blockchain things that either cost money or huge amounts of bandwidth and compute.
Self hosted, with decentralized identity not tied to a domain name, with automatic backup and redundancy to a selectable cloud provider via an open source protocol, with a very high quality mobile app, and smartwatch support, etc, would be amazing.
But it seems like people these days aren't interested in feature rich commercial style zero maintenance apps, so I'll probably keep mostly ignoring the entire concept of self hosting until that changes.
People are really focused on privacy, and even opt-in integration with nonprivate hardware and services doesn't happen much.
Convenience features gtt completely ignored, and worst of all, a huge amount of P2P stuff has no mobile support.
Furthermore a lot of it involves a self hosted single point of failure. For me that's a complete deal breaker, it's not acceptable that a service could go down because something happened to a home server while I was away.
And then on top of that, most p2p projects for about 10 years were completely impractical blockchain things that either cost money or huge amounts of bandwidth and compute.
Self hosted, with decentralized identity not tied to a domain name, with automatic backup and redundancy to a selectable cloud provider via an open source protocol, with a very high quality mobile app, and smartwatch support, etc, would be amazing.
But there's not much interest, and it basically can't be done in a UNIXy way, since a lot of the value the clouds provide is in the tight integration of everything, with voice assistants and calendars and a million little things that are individually maybe not even worth setting up manually.
See also Cloudron, Yunohost, Umbrel.
hmmm, feels pretty unpolished to me
https://github.com/sandstorm-io/sandstorm-website/commit/9e0...
I'm a systems engineer, not a web developer. :/
I told her that in the best case scenario, the future will be homes with a redundant hosting server where everything lives. Families will host their own email, calendar, photos for sharing. And cloud will only be used for backup in case of a disaster, or for migrating.
If you rent an apartment, it will someday come with a hosting service as part of the home address. And features will vary based on the kind of apartment or flat you're renting or buying.
And of course, you can upgrade it.
Mac OS X provided self-hosting of calendars, contacts, DNS, email, and websites with the Server app [2] starting in 2011 but it was discontinued in 2018.
[2]: https://en.wikipedia.org/wiki/Mac_OS_X_Server#Server_app
What are your other favourite episodes? :D
Once you've gone to all the other trouble, pay a little extra to the ISP for a static IP, and then any computer is your own "cloud"...
Putting the hosted machine in a separate VLAN (like a guest network) can mitigate that, but it means you have to do that configuration correctly.
(I am not confident enough in my own abilities/knowledge with respect to these vulnerabilities to try it, and so it may turn out to be very straightforward. I hope to do something along those lines someday but so far the risk has outweighed the reward for me.)
Behind this, any pirated server could decide to send VLAN tagged packets that may go trough the firewall if the rules are bad, or read any of them arriving to it.
VLAN's are useful if you want to "tag" packets with ID's going trough specific interfaces for segmentation purposes. The tag is applied from the interface standpoint, so this gives a virtual segmentation between ports of machines you are supposed to always control, like between a port on your router and ports on a managed switch.
In this case VLAN's are configured on the router's interface and the switch interfaces, but the exposed server is not aware about it, and can't change it, so you can know the ID is right.
This is often believed this is required to isolate networks, this is wrong, you just need to have separate interfaces.
For instance, here is everything I do:
- Use an open source firewall+router (== Opnsense) and not commercial routers (such as Netgear, Tp Link etc.) - Open up port 80 and 443 on the firewall. - Both the ports go to a Traefik reverse proxy that is configured to always redirect port 80 to 443. - Traefik then reverse-proxies requests to relevant Docker containers. - Auto-update Traefik every day (through Watch Tower). - Use Authelia, with 2FA, where I can for the publicly available services.
I assume I am reasonably secure but I've also built this over a few months. You may not get there right away, so start small and slow and don't go crazy early on.
The section 'More Indie Tips' is great, especially if you don't plan to follow the guide: https://sive.rs/ti#indie
I just want to throw out buyvm.net as a block storage alternative. Not as big as vultr but super reliable and affordable, they have a discord and the owner is great
Yes, you should strive for that, and you start by learning. Contrary to popular belief, you don't need to be a linux ninja to be able to host your own website and calendar.
The stuff mentioned in this article are the bare minimum, and you should want to do it yourself without being spoon fed the steps.
With that aside, this is exactly the kind of guide I would expect a three-letter agency contractor or worker to spread in order to "help you" stay off the grid, then unceremoniously drop a disaster on your head.
I mean, yeah it's a minimal step by step guide that just feel to be the poster's own todo list... As there's many like that. To get some entry-point information this is great but this is far from being useful in practice.
Basically it hides everything useful to know behind a big script that the intended reader is not even supposed to understand.
I did not have seen any protection for what's come from WAN, not even basic logging, investigation nor debugging methodology. No real backup methodology as well and the guide seems to not take system upgrades very seriously by saying "oh, it could run so for decades, but if you want you can do system upgrades".
This is obviously false to any expert and a very risky approach. This is not how we are supposed to teach internet-connected services self-hosting.
But so many people were getting stuck and frustrated trying to type in all those commands, (and mistaking "l" for "1" and such), that I realized I could help more people have their own server if I put most of those steps into a shell script.
Hopefully it'll be enough to give them a taste of the benefits of having their own server, then they can learn more about the steps afterwards.
There should be a product that you can buy (a computer) that you bring home, plug in, set up via your phone or computer that:
- can host websites
- can store your files and sync them to other devices
- control your home automation
- host your email
- anything else you might otherwise put on a server
And does it all EASILY with a simple phone or web UI.
Yes I know you can actually buy a computer or server or raspberry pi and put something like NextCloud or Home Assistant et al. on it, but the real barrier imo is the setup and configuration. Even I don't do all this because it seems daunting to configure all of it, and I consider myself a pretty technical person. I really just want to buy a box, plug it in, and like select which apps I want to use, and then it starts working for me.
Or not. I would much rather have something commercial (built on open source) like this so I can be more at ease that my data is safe, compared to doing everything myself.
How will they pay for maintaining all the apps and making sure that they are properly integrated into the platform as they get updated?
[1] it's quite difficult to run your own e-mail servers these days, making it trusted by the rest of the world is a lot of work
Keep in mind that there's many people self-hosting and exposing services to WAN that ends as spamboxes or worse from misconfigured bits.
The thing is non-techy people would setup such thing and get it running, but have no technical way to maintain it. It's a flying plane in automatic mode with no competent pilot inside.
Spam pretty much destroyed e-mail as an actually open protocol. Spam destroys all open systems.
But the reader should be aware that these writeups of how to do X often involve the writer/publisher getting referral kickbacks from the commercial service they're describing.
I'm about to be in a position of doing something like those writeups, as a microstartup, and I'm not entirely comfortable with the affiliate programs. But the companies monetizing with privacy-invading ubiquitous profiling trackers (sometimes euphemistically called "showing ads" and "analytics"), and otherwise selling personal data, have spoiled most potential willingness of readers to pay for content. So, affiliate programs with an obvious potential conflict of interest is the only way I've thought of to fund the work.
More info if interested: https://sive.rs/trust
Yes, I get a lot of email. But it's almost all transactional or subscription. The number of emails I send or receive with other humans is pretty dang low. Most institutions these days require using their platform for communications. Most people I care about who I communicate with electronically I do over SMS or Signal or occasionally a Mastodon message.
I still own the domain, so I could easily pick up up and move to a different mail service in probably just several minutes of setting up an account and changing some DNS values. So while not fully independent, the time spent getting outbound email right is going to have less impact than other changes I could make.
But then Vultr.com is not un-blocking port 25 by request anymore.
That's why I had to switch to a SMTP service.
Nothing to be afraid of, here, that I can see.