How I built this website on a Raspberry Pi
mirawelner.com
mirawelner.com
Instead, they took the simplest possible route that works: installing the web server on bare metal, serving plain HTML and CSS, and using direct port forwarding via the router. This was a delightful read.
On top of a Linux distro is not what people usually call bare metal
As much as I look back at the simplicity (Apache config was not that difficult for a small site, at least with Apache 2.0), the part of me that operates production software these days gets anxiety the idea of it all.
And yet, when I wrote a small website to host my wedding website last year, it was indeed Linux, (some webserver), Postgres and PHP, with me copying files manually to FTP. It was probably nginx but you know what, I paid a company £50 for a large amount of storage, bandwidth, a domain and SSL certificate, for year, and everything went dandy. Horses for courses and all that.
Sure, languages evolve, but that doesn't mean "anything goes" -- to the contrary, novel mutations have to survive intense selection pressures in order to eventually become part of the standard language.
Where new ways of using existing terms create ambiguity and conflict with existing meanings, their survival chances aren't always great.
This use of "bare metal" does contradict the pre-existing meaning, so is not quite appropriate. What is valid is describing the OS itself as running on bare metal in contrast to running within a VM/container -- but an application running on top of that OS is not running on bare metal.
This isn't particularly egregious, though, since there are negligible cases of actually running applications on bare metal today: if you are talking about applications, the context can usually explain the intended meaning. But that wasn't always the case in the past (PC "booter" software used to be common), so this doesn't necessarily apply retrospectively, and may not be the case in the future, especially considering some of the interesting things companies like Oxide are working on.
Three years ago, I tried to publish a website on a VPS in the morning to present it to a client at lunch. This was before ChatGPT. I spent hours trying but got nowhere. At the meeting, having failed to publish it, I had to run it locally and share my screen. I was frustrated.
Later, I discovered Heroku, which solved all my problems. Eventually, I migrated to VPS + CapRover, and now I use VPS + Coolify.
I’m happy with my setup—it works—but I’ve always felt guilty for not knowing how to publish a simple website without Docker.
However, with tools like Caddy and Let’s Encrypt, the process has become easier. That said, it still involves quite a bit of fiddling if you want to automate everything and make it reproducible without a lot of hassle. Now, I do it all the time for fun. But that said, if it's a static site, then I don't see much point in self-hosting when Cloudflare Page and GitHub Page are so much more convenient.
If you’re using Apache2 you might also want to look at mod_md, not just certbot: https://httpd.apache.org/docs/2.4/mod/mod_md.html
Also, if you want to minimize the amount of JS, then just drop jQuery and use fetch, it’s reasonably pleasant too: https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API
Lovely article!
I’ll look into fetch and mod_mt - they seem helpful!
Things I learned:
- set the pi to reboot on poweroff
- Given this was TV used the AV output on the PI displaying in NTSC 4:3 (to support customers with older TVs), so had to be aware of overscan margins
- Added a startup script to start chromium in kiosk mode and open the slider page for the show side. worked 95% of the time, if not just power off then on.
- part of the troubleshooting was just unplug and replug - but SD cards will choke on too many power cycles, so instead of SD use a USB->SATA cable and a regular spinning rust HDD - slower but VERY reliable, the journaling file system can recover after power-outage.
- Get the right USB->SATA cable, USB-3 models seem to be more responsive and the PI can boot from them, there are some are too slow and the Pi will fail to boot.
- Slider had it's own login page (outside of CMSimple) to remotely manage the slideshow.
- Also changed the SSH Port to something uncommon to thwart bad guys.
Curious how you handle your router’s public IP changing as (I believe?) this is pretty common depending on the ISP, no?
Theoretically, routers have public IPs that change often and you have to buy something to make sure they don't.
In practice, this has only ever happened once to me when my router got hacked and I had to get firmware replaced. So while its a major issue if you have a huge site that needs to be reliable, if it is just a personal site it can be okay to just assume it will never change, and if it does you can always just get your domain name to point to the new IP.
It may be worth it to look into something to make it more stable, but right now it just isn't worth the extra fee.
Edit: Njalla supports dynamic DNS records natively[3].
[0] https://en.wikipedia.org/wiki/Dynamic_DNS
[1] https://freedns.afraid.org/
Also I can tell this post was a good post because people are using he/him pronouns for me in the comments lol. What a world we live in :)
Initially, I used it as a CUPS server to turn a non-networked Brother printer (HL-2240) into a wireless printer after Google discontinued Google Cloud Print.
The printing project was a lot of fun and inspired me to dive into another challenge: self-hosting. Along the way, I learned a great deal about Apache, SSL certificates, security, and just how fragile SD cards can be!
The print server still works well, though I’ve since downsized to a Raspberry Pi Zero W.
I highly recommend firewalld instead.
I know it's not strictly best practice but store your private key in your password manager. That way if the worst happens you aren't up a creek...
2FA cannot help you in all cases.
Make sure you have updated firmware to latest, plus added active protection against the following known vulnerabilities.
https://nvd.nist.gov/vuln/search/results?form_type=Basic&res...
So for example when my router was hacked I installed fail2ban, when a friend told me my mobile view was terrible I read about CSS, I have just been working on it gradually but I have never worked in webdev. Just today, a commenter here suggested I implement an RSS feed so I had to look up how to do that and now I have an RSS feed! I'm just learning things on the fly. I'm glad you find it impressive, I just find it as being the lazy way to learn.
I’ve tried a few other approaches in the past and this seems like the simplest, given a familiarity with git.
To be honest, you can have both good and bad configuration in either.
I recently migrated one stack from Nginx to Apache2 (where an Nginx container would refuse to start when it was a reverse proxy for say 10 services and one of those took longer to start meaning that it had no DNS records, so Nginx would be in a restart loop and the other 9 would be unavailable) and it was fine.
If you choose to do smart things like caching and such, that opens a whole new can of worms, but basic "this is my HTML page" stuff is typically "not-unsafe" (as opposed to "safe").
Basically, you can have a computer available online through Cloudflare without having to open any ports, as it makes the computer available through outbound connections. Should also make it possible to host behind CGNAT.
(was down for me, this fixed it)