I ended up going with Ente and have been pretty happy with it.
I might also just switch over to Ente so I don't have to deal with the self-hosting. Price for Ente is about equivalent for what I'm paying Hetzner right now.
I also use Immich, but on a local server (using tailscale to reach it from outside)
I’ve previously experimented a bit with encrypted volumes that I manually decrypt over ssh, and even full disk encryption that I manually decrypt over ssh.
My experience with Hetzner has been good. It is really rare that the servers go down on their own. Reboots are usually my own doing, so I am already “around” to decrypt encrypted volumes.
I have experienced critical, unrecoverable hardware failure on Hetzner servers a couple of times over the years. But I’ve had offsite backups in place since day one, so I never ultimately lost any important data. Had to deprovision the broken server, reprovision a new one and restore from my offsite backup. Which is a bit of a hassle, but no biggie because the only one that relies on my servers is mostly myself. A few days of downtime because I am too busy to set up a new server right away is therefore also ok for me, with how infrequently it has happened.
A single Hetzner server should never be the only place hosting a copy of all your photos or other data you cannot afford to lose. But that applies to any host really. Not unique to Hetzner.
Hetzner (or any vps provider) should not be a place at all to store ANY copy of your photos, unencrypted.
I agree that they respect privacy a lot, they're probably the best of all the service providers when it comes to your data and that there are data protection laws in place etc etc
but in the end, it's your personal photos, I wouldn't be willing to upload it to any provider unencrypted, good that you're encrypting
Also, check this out (not my project): https://github.com/rfjakob/gocryptfs
How do they handle such situations?
I think there was a form asking for reason for cancelling the server and I ticked something like “other” and left a note for them saying that there was hardware problems. So I would assume they have a look at it, replace the bad components and then rent it out to someone else.
Monitorering is then your responsibility. They have no login/account on your host.
For any hardware issues I have had I have simply created a support ticket. They have always been really fast at responding and fixing for me. If you report a disk and serial number it gets swapped in no time.
They have managed offerings as well. I have never used those.
No, it's really a temporary solution. My ideal setup will be having it on a local server w/ encrypted backups to Hetzner (or Backblaze or whatever) but I need to acquire the hardware for it and got fatigued with de-Googling so I put the project on hold as "good enough" for now.
If anybody does manage to get a hold of all of my photos... I won't be too heartbroken about it. It would be creepy for somebody to have them but there's nothing incriminating in there and it's literally 90% pictures of dogs and cats (and 9% landscapes/flowers, 1% people)
I don't use arch but this looks cleaner than whatever Debian or fedora (both of which I use) have going on
Also when I have it on my private DNS stops working, which to be fair I haven't put a huge amount of effort into solving yet.
I love it for things like ssh to a server at home, but for things like hosting a service I prefer something like cloudflare tunnel or a self hosted reverse proxy. Though tailscale funnel looks promising.
It's a good idea to have backups/multiple copies regardless of what system you're using.
https://github.com/simulot/immich-go is what I used to import ~300gb of photos from Google Photos to Immich. Not sure how well it works for iCloud.
There is also https://ente.io/ which is a private & secure photo backup app that you don't need to self-host.
iCloud Photos stores originals (assuming you're using "Download Originals to this Mac") in the "originals" folder of your .photoslibrary package.
If you don't sync your originals, use iCloud Photos Downloader (https://github.com/icloud-photos-downloader/icloud_photos_do...) to get them.