Self-Hosted Is Awesome
pixeljets.com
pixeljets.com
I use a very similar process, and have found this to be a godsend in making it even quicker: https://github.com/lucaslorentz/caddy-docker-proxy
It handles the routing to multiple dockerized projects on one server, by scanning docker compose files for labels and automatically setting up the required caddy configuration.
- Nextcloud personal file sync and calendar mostly
- FreshRSS rss reader
- Dokuwiki personal wiki
- Shaarli for bookmarks
- Mealie for grabbing recipes off the internet and keeping them
- Metube for archiving youtube videos
- Gitea - personal github
- Drone for builds
There is so much available nowadays for self hosted webapps and a lot of it is genuinely great.
I prefer simpler/less abstract container technologies like systemd-nspawn or LXC. With those I always know what’s actually happening on my system.
Docker is IMO too much black box and voodoo.
LAMP, MEAN, RoR, “bare” php scripts, binaries with super-specific requirements, running multiple apps on bare-metal…
Truly trial by fire.
In my opinion, setting up LAMP is easier than Docker.
Setting up LAMP is just copy-pasting a few install commands:
apt install apache2 php libapache2-mod-php mariadb-server php-mysql
mysql_secure_installation
ufw allow http
ufw allow https
ufw enableI also like using proxmox with Turnkey Linux's images. Helped me self host invoice ninja faster, or at least try it out.
I feel like between Portainer and Proxmox it can cut some of the pain of getting something off the ground.
I do recommend editing Postfix to not filter out Spamhaus and instead configure Spamassassin to assign large points to Spamhaus listed domains. I realized this when the Dovecot list was being flagged by Spamhaus as spam and the list admin (with a dovecot.org email address) informed me that his server never sent spam and they owned the IP address and could not get anyone at Spamhaus to respond. If an email blacklist manager can't provide a meaningful way even for dovecot.org to be removed from a blacklist, and especially when there is no clear route for an admin to fix issues and be removed from a blacklist, then the blacklist cannot be a trusted gatekeeper for a mail server, which is how the Mail-in-a-Box project and many admins configure their servers.
What are some of the common infrastructure concerns it handles for you out of the box?
I preferred to start with an empty cluster and to add in the functionality needed.
I run a single intel n100 node running Fedora Core. Initially it was a lot of tinkering with IaC / yaml but once I had a working setup, I spend most of the time merging PRs from renovate from my phones GitHub app that keeps the software updated.
Some supporting benchmarks.
https://www.scitepress.org/Papers/2020/93404/93404.pdf
https://programming-group.com/assets/pdf/papers/2023_Lightwe...
Another issue is keeping up with issues affecting a project. I treat all projects updates like alphas, and I don't install the update as it becomes available because the inconvenience and time cost to restore a borked server is never worth whatever perceived gain there is from the update. But this means I need to minimally have things like mailing list subscriptions, GitHub project subscriptions, etc., so the information comes to me without my having to go out to actively review the information. I set up folders for the lists and it is usually 1-2 minutes per day just reviewing the subjects and occasionally skimming an issue that might be relevant to me.
- Jellyfin. self hosted media streaming AKA "selfhosted Netflix"
- Moonlight. Stream games from PC to TV/laptop/phone. AKA "selfhosted stadia"
- HomeAssistant
Personally I do have anything at home without docker at all, using NixOS to ease automation and replication and safe experiments/changes + zfs for ease storage. I do feel the frustration of using modern platforms instead of classic ones like Emacs and simple file sync/sharing: they can't really be integrated without spending enormous time in reading rapidly changing codebases with way too much deps and boileplates so essentially I tend to advertise AGAINST the idea of locally replicate a "cloud" model instead of a classic desktop one. But it's still interesting to read.
Now, I recognise that everyone is different and values different things in life, and there is no problem with that. Personally, I go for a hosted solution if it requires more than 1-2H of work per month from me or a member of my staff, which, in my case, happens to apply to all software.
So far I'm pretty happy, zfs makes incremental backup easy (one command - zfs send ...). I also keep a restic backup of the docker data directories in case zfs has a flaw.
Keeping it up to date is easy with watchtower. So far pretty happy.
I'm currently self-hosting 10 different applications on my local server, which represents everything I've ever seen that looked fun or useful to me. Every one of them had a Docker image with an example compose file, which means updating them just requires periodically running Renovate [0] on the repo that stores all my compose files and then running a script that docker compose pulls the updates. It takes maybe 10 minutes every other week, and is actually kinda fun.
It helps that all the apps are only accessible from within my VPN, so I'm not too worried about fixing security updates within a tiny time window.
Naturally, this kinda sucks, because some things are harder than they have to be, but then again, we are moving so far away from the nuts and bolts of it all that we barely understand how anything works. But I would personally argue that is most of the civilization anyway.
On the other hand, if the user wants 'easy mode', it definitely exists for most purposes. At the end of the day, its all about use case.
For me to self host something, there has to be some value add. I generally don't want to self host things that are commodities. I'd rather focus my time and attention on things that actually add value.
Nice one.
Seems on the one side you have this alignment with the service provider. And for the future you hope they don’t zig when you’re zagging.
On the other side, you already have some IT responsibilities with hardware acquisition, maintenance and networking.
You hire this out too, if you can afford it or don’t care about ‘technical’ things.
- Audiobookshelf (https://github.com/advplyr/audiobookshelf) for audiobooks & podcasts
- Wallabag for links
- COPS for ebooks
- synchting for syncing across devices
It takes more time to host/support it, but I've learned a lot while doing it and knowing that my information is mine and I won't be "discontinued" is worth the time.
Everything is Apple/iCloud now. Fuck it - not my problem. I can go on holiday for two weeks now and if anything breaks, someone else will fix it.
Used to self host everything (except mail), and spent hours and hours keeping it patched and running.
Some years ago i “did the math” on it, and it made absolutely no sense self hosting anything. Just keeping a small 4 bay NAS running costs around $20/month over 5 years (including cost of hardware, power alone is $10 at 40W) or around €25/month in Europe.
Add to that, that when your user count exceeds 1, you suddenly have a SLA, so no more spare time for you, or a lot extra cash in hardware and power.
These days I’ve thrown everything in the cloud, and just use the “big cloud” (iCloud/OneDrive/Google Drive/Dropbox/whatever).
You main threat in a cloud scenario is loss of access to data (as opposed to loss of data in a self hosted environment), and i mitigate that by backing up data at home as well as with a different cloud provider, and have a 3-2-1 backup setup in place.
All i have left at home now is a small energy efficient server that synchronizes cloud data locally in “real time”, and makes somewhat frequent backups of that data to another small server (Raspberry Pi) at home, as well as nightly backups to another cloud.
The price of “running” it is less than the cost of power consumption of my old self hosted solution, and as you said, fuck it, i can go on holiday for two weeks and not worry about it. My server will alert me if stuff goes wrong, and Healthchecks.io will alert me if my server stops doing its stuff.
As for privacy, i use Cryptomator to encrypt sensitive stuff. Cryptomator provides transparent encryption on both desktop and mobile platforms, and registers as a file provider in iOS, so it’s just a matter of selecting a different storage location , though I’m not overly paranoid, and most stuff just uploads “as is”.
Beyond that, it’s a time sink, with configurations, broken updates, patching, security, networking, troubleshooting etc.
...an engineer self-hosted stuff on his iMac.
Months have gone by...
...before LinkedIn realized their lost millions of user data records.