The often maligned “setup wizard” UI a lot of us remember from not so long ago actually was kinda neat in many ways.
Run “I want a website app” and click through a few simple menus that ask you questions to get you set up with a domain, email, hosting, etc. The defaults would be a selection of ideally smaller/non-FAANG providers, with some power-user menu or some shit gated behind a checkbox.
Then it just saves a document with your new CMS/etc logins, and away you go.
I guess you could even make a few bucks off it by using referral codes or whatever to fund development cost.
True, in the literal sense that you will have to administrate your own system, but I'm sure there must be ways to make this easier for people. Perhaps small computers that come pre-configured with the correct specifications for being a good small-scale server and pre-installed with software that provides a simple web GUI dashboard that you can just drop files on and it will serve them up for you, with everything else taken care of under the hood.
> applying software updates all the time
With image based distros, containers, and their respective auto-updating schemes, this — and the concomitant problems updates may bring given the extensive and hairy state of most systems — should hopefully become a thing of the past.
> patching emergency security vulnerabilities
I mean, unless you are running something that is incredibly visible online and linked to you from a lot of places or used by a lot of people and so you need to take extreme extra security steps, shouldn't this be taken care of by just regularly updating your software? For a small scale self-hosted blog or personal email server this seems a hardly proportional.
> hardening services against constant attacks
Again, it seems like you are projecting the requirements of a much larger scale endeavor onto small-scale personal self hosting of a blog or email server only you use. And to the degree that system hardening is necessary for a small cell posted system, once again image-based operating systems with hardened Pam authentication rules that run everything in rootless podman containers and keep SELinux enabled should be more than hard enough and all that can be configured and set up upstream to the user.
> deciding whether the daily "I have found a bug in your system and will disclose" mails are legitimate threats
What are you even talking about here? For the third time, it seems like you are projecting the requirements of a much larger scale thing onto small-scale personal self hosting.
> If you fail at any of these tasks, relatively new regulations mean various governments can fine you more than your net worth over failing to report a data breach to the right agency on the right timeline
A data breach? On a small self-hosted blog or email server? Who's data would those regulations be punishing you for leaking, your own, maybe two freinds'? And those regulations, if you are speaking about the ones in the EU that I am thinking of, have pretty clear cut offs and requirements and stuff that really wouldn't apply to someone's little self-hosted thing.
Great minds think alike. See FreedomBox[1] for a totally FOSS implementation of that idea; one of my friends runs all of his internet services at home with it: email, file storage, contacts synchronisation etc.
Say you host your own WordPress blog with comments enabled. A few of your posts get to the front page of Hacker News, and you collect a couple hundred comments from California techies. Your WordPress instance is breached because you didn't patch a zero day vulnerability quickly enough. You have to personally notify every California resident of the breach, and California's Attorney General.
Government regulation means that part of your job in self-hosting a simple blog is knowing that CCPA exists, along with every similar regulation passed by every other state, now and into the future.
Worse, you may not even realize you're holding regulated "personal data" and how much. Maybe you try to avoid this liability by turning off comments and uploads, but you don't realize your web server has access logs enabled, and some state or country considers this personal data as well. GDPR does for one.
The possibility of this is less than 1% purely due to commenting friction. Hacker News already has a comment section. No one's going to sign up for a Wordpress account in order to post their comments there.
And if one doesn't?