Ziglang.org migrates from AWS to self-hosting
ziglang.org
ziglang.org
How so?
(Good move IMO nevertheless)
But they said on prem. Hetzner or any other data center is not on prem.
Ah.. TFA is on a Hetzner vps. Well it's 2 different conversations anyway. TFA doesn't say they did it for security but for efficiency.
* Less prone to human error. We have one well-secured, central firewall that only a few developers can access. So, even if a developer forgets to properly secure something downstream, it will still be protected by the firewall. One could argue that this is possible in the cloud, but managing VPCs, etc., introduces risks. There’s always the possibility of something critical being left outside the VPC. On-prem, there’s no way something can physically escape our ethernet cables.
* IAM and bucket management issues. Anything in the cloud is inherently exposed to the Internet and, in most cases, open by default. You need to manage countless IAM configurations.
* Physical inspection. We can actually look at our setup, and if necessary, visually inspect if a server is physically encrypted.
* Simplicity and transparency. Things are simpler and more straightforward: Storage is storage, a disk is a disk, and ethernet is ethernet. Canot stress how beatufill this is, even with 100 servers it easy to manage them than in the cloud.
* Modern open-source software. Modern open-source solutions have incorporated many smart features from the cloud, making on-premise setups more powerful and easier to manage.
They get thousands of doom-scrollers every day, and their revenue was ~$55M last year.
Admittedly, those numbers are peanuts compared to some global SaaS providers.
But they managed to work for decades on two moderately beefy servers, and a database server, behind a load balancer.
Heck, one server was always enough. The second one was there for redundancy, during releases and in case of emergency.
Traffic peaked at 80% during nation-wide flow-tv commercials. As flow-tv is on the way out, the traffic has spread out a lot more.
They used Perl, which isn't insanely fast, it was just well-made (enough caching, no N+1 queries, etc.).
"That point" where auto-scaling is the obvious choice is pretty far out.
Us on-prem regular server people are hard to find.
I whish there was more ressource to learn this "low-level" approached to web developpement.
It is sort of interesting we are back to torrenting. Especially when bandwidth outside of the cloud are relatively cheap. I wonder how many TB they are using per month.
ping -6 ziglang.org PING ziglang.org (2a01:4f9:3051:4bd2::) 56 data bytes ^C --- ziglang.org ping statistics --- 7 packets transmitted, 0 received, 100% packet loss, time 6135ms
just noticed because zigup has failed..
Here's a little more info on this, because it's fun: it looks like Hetzner give you a /64, which by convention is indeed the size of one IPv6 subnet. That's also the minimum size block any IPv6 provider will give you (the spec essentially requires this). My ISP gives me a /64 by default, but upon request will route a /56 or even an entire /48 to me, meaning I can actually get a block of 65k subnets, for free. Hell, if you're on an IPv4-only connection, you can set up a tunnel with Hurricane Electric and get a /48 for free -- that's what I did for several years!
IPv6 is pretty objectively amazing -- huge address space to the point where we can just give people a few hundred or even thousand subnets if they need them, no need for NAT or the accursed CG-NAT meaning IPs are actually globally unique, stateless client configuration (SLAAC), backwards-compatible at the software layer via IPv4-mapped addresses, probably more things I've forgotten...
Unfortunately, the world has been slow to figure this out; there's no real incentive to migrate. You can find the global IPv6 stats online, but as a personal data point which surprised me, I can tell you (unless it's changed in the past few months) that the University of Oxford's network (which you'd expect to be pretty modernized!) is still entirely IPv4-only.
I would argue that is the fault of ipv6.
Heh.