DigitalOcean Sucks. Use DigitalOcean
raymii.org
raymii.org
Some features we really want to see are when upgrading a droplet, the ability for the disk to increase in size. Right now, you have to image it, delete it, create a new droplet from the image, and pray that you keep the same IP address. Not a suitable solution for companies relying on uptime and stability.
Second, when creating a droplet, the ability to check a box, "ensure this droplet is provisioned on a different hypervisor then the rest of your droplets." Again, when building a highly available cluster, does absolutely no good if they are all on the same physical machine.
Finally, the ability to attach multiple ip addresses to a single droplet is a must have.
With that said, thanks DO, you guys rock!
The IP thing is definitely annoying especially since you're never guaranteed an IP (say you want to switch VMs) even in the same region. That and hard drive size which has definitely made me pay more than I should (when I don't need that much CPU/RAM but need the disk space). Otherwise great experience with them.
I'm not usually vocally supportive of companies, but they're doing quite a good job: this article is a little undeserved.
Personally, I hate new names like this for old things.. [1]
Stop making up names for things. My brain doesn't want to learn a new language for something that can easily be called by the legacy name. It's wasted time and slows things down. (I'm exaggerating a bit of course but why do I have to learn something new of no value to me? And I'm reading this and someone is commenting calling things droplets and now I have to do a search to find out what a droplet is...)
Reminds me of some of Spike Lee's first films where he was more concerned with coming up with some creative oddity that could be linked to him. (If you've ever taken a film class you probably remember the prof talking about something that Hitchcock was doing in the film that had never been done before.)
[1] From DO website: "DigitalOcean calls its virtual servers, droplets; each droplet that you spin up is a new virtual server for your personal use. "
But while it is an easy word (and it's "cute") it is different and strictly for branding over something that already is well understood and known. Why do it?
Plus, it's just one word, not a whole new language, so not really that much of an issue, especially compared to some of the heavier offenders out there.
"Instance" has a very well defined meaning, which leads to some standard implications.
It means one particulate <thing> out of several, which are all alike. It implies that your <thing>, and in fact all <thing>s, has (have) no physical reality. It implies that <thing>s can be created and destroyed at will.
It is also completely generic. You can have EC2 instances, ${APPLICATION} instances, object instances (in absolutely any object-oriented language, and several that aren't), database instances, etc.
A virtual private server is a cheap knock-off of a real physical server. A server instance is something you get from an API instead of having to hire a guy to plug things in.
Many people seem to think that's a smarter-sounding alternative to "appropriate", but it's really a completely different word. Just use "appropriate".
It is true that "appropriate" could have been used instead, but I chose a different word and I believe I used it correctly, thank you very much.
http://english.stackexchange.com/questions/21101/does-apropo...
for examples. Using "appropriate" would have been better. There's no need to thank me ;)
Even if I had been wrong, this kind of smart aleck, nit-picky comment would not be welcome. But based on the fact that you apparently just linked the first result for "apropos" on english.stackexchange.com even though it's about a completely different part of speech, I don't think you actually know enough about this topic to comment on it. So you are both needlessly hounding people about irrelevant trivia and spreading bad information. Come on, dude.
I have no interest in your "points". I don't care how you thought you were using it. I don't care that you think you were right. I really don't care about the whole thing at all. I simply told you where you were going wrong, so feel free to ignore it if you wish to remain wrong, but you were still wrong. Go learn something.
That link does not address the word's use as an adjective at all except to note that it can be used as an adjective.
> I have no interest in your "points". I don't care how you thought you were using it. I don't care that you think you were right. I really don't care about the whole thing at all. I simply told you where you were going wrong, so feel free to ignore it if you wish to remain wrong, but you were still wrong. Go learn something.
I quoted OED to support my usage. You linked to a Stack Exchange question asking whether the correct prepositional form of apropos is "apropos" or "apropos of" — when I wasn't even using the prepositional form. If you were in my shoes, would you listen to you?
I never sought your approval. You just came out of the blue and told me I was wrong.
> Your usage was wrong.
You are wrong. I don't know why this is so hard for you to accept. Unlike you, I have presented actual academically acceptable evidence for my claim — you might take that as a clue for who's right in this situation.
> If you don't like that, go find another opinion.
I did get another opinion — I looked the word up in the Oxford English Dictionary and it confirmed that I used the word correctly.
If they'd have called it a Virtual Private Dedicated Serverlet or invented yet another useless acronym (YAUA, of course) I'd be agreeing, but droplet is simple and easy and as a bonus helps avoid the immediate "This is too techy for me!" attitude you can get when trying to convince a shared server user that the reason their site keeps going offline is because they need to upgrade to something better
I've written a short blog post about the over-use of buzzword in software here: http://timbenke.de/?p=881
So yeah, love the feedback and actively working every day to bring any suck to zero.
Can you disclose what kind of allocation each instance or each customer will get? Hopefully, you guys will be much less stingy with them than Linode, and give each customer a /48 to allocate freely between the individual nodes.
I am a very happy customer currently and am looking to use DO for my next project which involves heavy use of your API and lots of concurrent instances. As a customer I can testify that your product is a fantastic value for the price. Keep up the good work!
I think our allowances will have to be sorted out a little down the road but /48 is easy to acquire (unlike ipv4 where we have to wait till we're at 80% capacity before we're allocated more IPs). ipv6 gets a little sticky when you start talking about the internet of things, there are a lot of new concepts introduced that we have to take into account when we're managing what is closing in on a million of the worlds public hosts. I don't see ANY reason why we won't allow a least one /48 per droplet. Part of our slowness on things like CDN, load balancing, failover etc are because we want the system to be really well build out to accommodate both ipv6 and the future of internet protocol addressing. While I can't speak for other providers, for us it's something we take seriously, but need to test all our systems together to make sure cloud 2.0 if you will works really we..
As I'm sure you know, we've scaled massively in the last 8 months and unfortunately the "lets just pop in a feature" becomes a lot more complex as the complexity and stability needs of our customers increase.
What I can say with 100% confidence is that there is a group of really amazing engineers working on this stuff and it's all in a roadmap, we just have to make sure everything is simple, stable and safe before we roll out.
I hope you can appreciate your measure in this matter. :)
I definitely appreciate that DO is doing things the right way and that this isn't going to be a rollout of "well, this host on this router supports IPv6, but that load balancer upstream does not".
I wonder if we could eventually get virtual routers between subnets without having to use droplets (like the virtual networking that VMWare/OpenStack are doing)
On a practical level, IPv6 is easier to administer since in a lot of ways it's more straightforward. For home use it's great since every device gets its own globally unique address (I can `ssh home.example.com` from any IPv6 enabled host).
Firewall rules become simpler if you have a common prefix vs lots of individual IPv4 addresses.
There are already lots of users who have IPv6 enabled: http://www.google.com/ipv6/statistics.html: TL;DR: over 2% of Google's traffic is over IPv6. Running dual stack servers lets you reach more customers.
I guess to an extent asking what people use IPv6 for is similar to asking what people use IPv4 for. You don't normally use IP. You use applications that run on top of TCP/IP or UDP/IP. Having a public IP address makes writing and managing those applications easier.
Edit: Also IPv6 addresses are cheap. An additional IPv4 address will run you about $1/month with a lot of providers. A billion IPv6 addresses is one billionth of the minimum allocation you will get for free. So in the long run, the cheapest DO droplet might cost as little as $4 instead of $5 :).
"Running dual stack servers lets you reach more customers."
Is there a single ISP in the world that is IPv6 -ONLY- to the end device?
The main advantage to running v6 on your servers (aside from being a good citizen) is that it allows you to distinguish individual customers for abuse detection, who'd otherwise be NAT'd to the same IPv4 address by their ISP. And ISP NATs are going to become more prevalent, because there just aren't enough IPv4 addresses to go around.
What IPv6 provides is an escape hatch; a path that avoids the NATs and tunnels.
The idea is that you want a dual stack environment where IPv4 and IPv6 coexist. Mac, Linux, and Windows all support this and do the right thing: if IPv6 is available on the client and server they try that first, if not they use IPv4.
Since you are asking I am assuming your ISP does not provide native IPv6. If you have a public IPv4 address that does not change more frequently than every several hours, the best solution is to set up a 6in4 tunnel (ignore any docs that refer to 6to4, different beast). Sign up for an account at TunnelBroker.net and create a regular /64 tunnel. What this will do is that your router will encapsulate your IPv6 packets inside IPv4 packets and send them to a Tunnel Broker router. That router will then strip the IPv4 header and send the packet off as a pure IPv6 packet. In most cases latency is measured in milliseconds and you might actually see lower latency since IPv6 servers and routes are currently less utilized. YouTube is certainly faster.
After you have your account and tunnel set up, it is best to set up your tunnel end point on your home router that supports TunnelBroker.net. Anything that runs OpenWRT does this, as do some commercial router firmware. OpenWRT is great for many reasons so you should use that anyways, this is just a bonus.
After your router is able to reach IPv6 hosts (google.com), you would set up and enable a service called radvd (router advertisement daemon) on your router. This will automatically give all the hosts on your LAN instant IPv6 connectivity.
Lastly, you would set up an HTTP ping to Tunnel Broker to let it know if your IPv4 address changes. Once again, OpenWRT does this out of the box.
I am writing this from my phone, so I cannot provide much specific advice, but email me at igor <at< igorpartola.com and I will answer any specific questions you may have.
Since I wrote my original comment, I went out and started doing more research into this. At this point, I have my main home server[0] now accessible via IPv6 using freenet6. However, I did apply for SixXS, so I can hopefully put my entire house on it (my router's an Asus WL-520GU, which currently has DD-WRT on it, but is compatible with OpenWRT). Though I'll be looking more into the Hurricane Electric service.
I'm really liking this, since now I can access my devices directly, without having to try to negotiate firewalls and weird subnets!
Thanks very much for the advice!
Re: DD-WRT, last I checked it did not come with an IPv6 firewall, ip6tables. I ended up recompiling it using what seemed to be Voodoo magic (match the arch, release, kernel version, etc.) OpenWRT comes with the firewall on by default and a web GUI to control it.
As for the different tunnel brokers (of which TunnelBroker.net is one), I should not assume you are in the US. Freenet6 is great. So is SixXS, though watch out to not lose credits and have your tunnel cut off. TunnelBroker.net is run by Hurricane Electric, has been rock solid for me and their support (for this free product) is fantastic.
Also, check out dns.he.net to set up reverse DNS, or just use them as your DNS provider. This service is also very nice and free.
[1] http://www.enterprisenetworkingplanet.com/datacenter/digital...
Personally I use Ansible http://www.ansibleworks.com/ and rdiff-backup http://rdiff-backup.nongnu.org/, along with Vagrant http://www.vagrantup.com/ for testing. So the day something happens with my droplet on DigitalOcean - I'll just run Ansible on a fresh server and restore the remaining data with rdiff-backup.
Yes, the lack of IPv6, being unable to use a virtual machines bootloader, a lack of a decent rescue image, and no private networking apart from one location sucks. However for the price - it's a good deal.
I'll know which VPS providers I have accounts with (and anybody curious could also find out by watching my zonefile updates), but at any time I won't care where the remote end of the ssh tunnels is or where the MX records are currently pointing.
I've done some thinking - but not (yet) experimenting with EncFS combined with S3FS to store encrypted mountable data on Amazon S3 (I'm currently useing EncFS to store data on Dropbox & GDrive and with BTSync). No good if you need fast local access to the data (you wouldn't want to run you database this way), but it would solve _some_ of those problems. For me right now - the answer is to store my own data at home, and relay access to that data when needed.
The "HN Discount" is still granted to new customers that know to ask about it - and we have always supported rdiff-backup, which you mentioned.
We support ipv6 in our Denver and Zurich locations...
The first of which was when my bank account suddenly got drained by a subscription plan to rsync - This later turned out to be an issue with the Paypal subscription, rsync refunded everything within an hour or so of me reporting the issue despite being on quite a different timezone, I was surprised someone was awake!
The second was that I was on somewhat of a very old contract (Going by emails I've been using them on this account since Sep 2010 and via nearlyfreespeech since March 2009, wow time flies!) and my storage space vs price was a bit off compared to their most recent pricing/HN offering. Quick ticket and within a couple of days everything was updated and I was on a much better pricing plan
More importantly than all of that, I've never lost data there - The only ever times I've been lacking a backup is when the backup was never pushed out to their servers in the first place due to my offsite script failing to run
As you can probably tell I'm a little bit of an rsync.net fanboy.. ahem :--)
For database backups, you need a consistent snapshot of the data - something which might not happen if you attempt to access the data directly. Add a script to your daily crontab directory, such as:
mysqldump --skip-extended-insert --all-databases --single-transaction --master-data=2 --flush-logs | gzip -9 --rsyncable > backup.sql.gz
Or:
sudo -u postgres pg_dumpall | gzip -9 --rsyncable > backup.sql.gz
Into a directory which rdiff-backup will download.
I always prefer to pull my backups from a local server I can trust instead of running a process on the server to push backups - if someone gains access to the server they could potentially destroy the backups if all the credentials are left on the server.
Other suggestions:
"Why John Kennedy would have loved Digital Ocean" "What Digital Ocean and the weather have in common".
Sorry I hate to joke and I don't want HN to end up just being people joking. But I had to point out that the title that gets attention is the title that gets your attention.
http://digitalocean.uservoice.com/forums/136585-digital-ocea...
It was last updated ONE YEAR AGO. Come on, that is outrageous.
After some back and forth my account was reinstated. It wasn't a huge deal but a shitty way to start my day. And after asking multiple times I was never told the reason why I had to go through this.
I had been happy until now. This just left a bad taste in my mouth.
edit: What pissed me off was having to send in a copy of my government issued ID.
For sure it's a pain in the ass and we've been discussing another verification methods, as I'm sure you can imagine, with adding 100s of accounts a day we need to make sure the public internet and our internal networks are relatively protected from someone spinning up vms for DDoS but also from compromised boxes and accounts.
If we publicly revealed how to trigger our verification process (that genuinely does a good job of protecting our network and customers) I'd imagine people would work to figure out ways to circumvent it. Occasionally we trigger a false positive, but I really believe that it's important to have this system in place.
I appreciate your feedback, and I'll make sure your comments get discussed at our next product meeting.
1: I wasn't notified that there was any problem with my account. 2: I have no idea what the repercussions of being suspected of fraud entails. Will my sites be shut down and if so then when? 3: I was only informed that something was wrong when I logged in and tried to give you money.
So what would have happened if I had paid for six months of hosting in advance (like I have done in the past)?
For fucks sake. Send off a email so I am not frantically backing up databases while waiting for my ticket to get replied to.
https://www.digitalocean.com/community/articles/initial-serv...
Don't miss "Step Five— Configure SSH (OPTIONAL)".
My assumption is that my droplet is considerably safer than it was to start with.
Next step: https://www.digitalocean.com/community/articles/how-to-prote...
Another edit: I got a helpful reply.
There has been a response to your ticket:
Greetings,
Unfortunately, we are unable to provide further information with regard to our backend abuse filters.
If we may be of any further assistance, please do let us know.
Regards, * Mitchell | Support Team
Because it's pretty obvious to me that people would create throwaway accounts to probe for all the fraud checks, then start creating abusive accounts.
A lot of people just use webhosting companies as a testing ground before magging a real card and going on a spending spree.
Anyway it comes down to the fact that its cheaper than any other large provider out there and almost always works very well. No one can beat that price with an actual usable service.
If I was going to complain about anything it would be the current lack of 2GB/4GB etc. droplets in San Francisco and the fact that launching a droplet from a smaller snapshot takes several minutes instead of one minute.
1. https://www.digitalocean.com/community/articles/how-to-insta...
https://news.ycombinator.com/item?id=6750630
Basically, mutt, postfix, procmail.
I opened a bug report about font rendering and text color issues in 2011. Not only is narrow text rendered oddly as you can see, but if you give it any color other than black, the rendered color doesn't match the color you specify in CSS. It can be way off, like blues rendering as purple. Last I checked, the bug was still open with no work done on it.
Any pro/con with that approach?
DigitalOcean's has been ignoring customer requests about this for 18 months on this:
https://digitalocean.uservoice.com/forums/136585-digital-oce...
It's really hard to take them seriously when you have to wait patiently for kernel updates that include critical security fixes.
The lack of IPv6 is a pain but I can deal with it. And the screw up with the NY2 network going down for a day kind of soured things as well.
What I'd really like is for DO to be a bit faster with feature development and more transparent on their progress.
I'd hazard a guess and say that people who often think they are on the bleeding edge aren't, and therefore get themselves into trouble.
With tools like docker, it's less about where you're hosting and more about being able to deploy to any infrastructure, as the only guarantee you'll have for the rest of your life is you'll be redeploying somewhere, be it with the same host or another one.
I think for what you pay, what you get, and the level of flexibility, DO is a great value and service in that it's not a random, small, no name vps provider that may disappear due to not managing their resources between the fine line of over or under subscribing.
Where I wouldn't get a Linode and recommend someone to get shared hosting, I can start them on DO and let them grow there, so I quite like the segment they've let me introduce dedicated VPS resources to.
I tried to set it up a few months ago, without success. Maybe things have changed since.
Something to do with DO using LXC with a setup that wouldn't work with Docker.
DO itself is a full VM virtualization and afaik is not using kernel-level isolation/LXC.
What advantage are you looking for?
I see that as an unacceptable risk really - one thing that keeps me from using DO. Other services also lack the reserved IPS sometimes, but some of them at least provide an integrated solution (LBaaS style).
Generally I'm quite happy so far. The setup process and the management panel is awesome while the CPU performance is lacking a bit. I/O performance (both disk and network) is great.
The sucks part fortunately havent affected me yet. I could use a little more ram but when I am there it could be changed with a click (and a reboot if I remember correctly).
If I had any complaint, it's that occasionally I get a droplet with a wonky IP address that seems to be shared with another host (like, the SSH host key wobbles between one and the other between invocations of ssh).
There was also some flakiness with NYC2 a couple of weeks ago, which caused some sadness and grief.
All in all, they're saving me multiple thousands of dollars.
If you're "in the cloud" (or hell, even if you're using your own bare iron servers), you need to be accepting that your server could just go away at any time (and Murphy's Law being what it is, probably at the worst possible time).
The real trick is figuring out how to handle backups and user data properly. It's easy to say "you need to plan for your main DB server going poof"; it's harder to actually make sure you can handle that without downtime and loss of user data. :)
Exactly this.
My little side project is fairly minimal, but users are paying for services. If the site goes down before my next backup, I'm going to have to reverse some charges (and look bad in the process!). One option might/would be to run failover on a $5 droplet, but then I also need to cluster Redis (server-side sessions), etc, etc... and it starts to become an "operations" side project and not a "product" side project. I'm using Puppet to automate the build process (and will build a "hot spare" image to get things up faster), but backups and failover are still tricky problems to solve.
1073741824 bytes (1.1 GB) copied, 3.84315 s, 279 MB/s
I was expecting it too be faster, actually. I get over 300 MB/s on a VPS with HDD at the company I work at. [1][1] https://true.nl
I wouldn't entirely trust any disk benchmark writing empty files, you might be running into some FS optimisations there.
And 300MB/s on a single spinning disk? No chance!
In terms of performance and cost, both are great. I haven't ever had any issues with Digital Ocean. With RamNode, they've had a couple of issues where there's been minimal downtime. And they had a breach back in June, but responded well.
I think I trust Digital Ocean more. The setup is easier and performance maybe slightly better.
While I'm sure it happens with DO as well, at least there I don't feel like they're active participants in the various VPS provider feuds that you see all the time over at LowEndBox.
TBH ALL the VPS providers are better than colo/cage suppliers from my experience who even at the high end are shit.
After running it two days, I receive an email saying their router find out that I was doing the DDOS and ask me to stop it. I stop the script immediately and reply them my reason telling them that I was doing it for University Assignment and I don't know that I was not allowed to do this. However, my account got suspends anyway. No matter how I send emails to beg them to give back my files in the server (I use the server for emacs and tmux to write codes for school projects), they just told me that sorry but my account is suspend. No matter how I beg them, all I received back from the email is just a max two line saying that my account is suspend. They do tell me that it suspends forever. After several days they deleted my account with all my files in it. Now I have no ways to get any of my files back! I feel ... so angry and hate so much about the digital ocean.
Is this how a normal American Company does? Will a normal American Company suspends customers account because that customer use it to do university work? I can understand it suspends me if I violate any laws but I was just doing an assignment and not violates anything. It also ignore the apology from the customer. Any evidence the customer provides is ignored gets well. Even that after couple days, digital ocean deleted that customer's account with all his files permanently!
This is my story. This is the reason why I hate Digital Ocean!!!!!!
Do you _really_ think you have a "right" to run a dictionary attack from someone else's network? _Seriously?_
Personally - from looking at my fail2ban logs, I wish Amazon - and even more usefully, large residential cable/adsl providers - would implement this sort of pro-active monitoring of user/customer behavior.
What penalty do the people attacking my clients' WordPress sites or SSH ports deserve? Would that penalty change if they mailed Digital Ocean saying "No, it's OK - me attacking that website is part of my Uni assignment!"? Who'd be responsible for checking that claim, and how much time would it take? And remind me again how much you'd spent with Digital Ocean?
You fucked up big time - deal with it and learn from it. There's clearly a whole bunch of things you didn't even think about before doing this (ad that you're still whining about and failing to accept responsibility for). Be glad it bit you on the ass for something as unimportant as a uni assignment - imagine how much worse this could be if instead of a few assignment files, you'd lost 6 months of your startup's code - because you hadn't bothered reading the TOS you agreed to and didn't bother keeping off-site copies of important files.
Sorry this is harsh - but seriously, think about this from anybody else but your perspective. You behaved like a jerk, then tried the "But I didn't know! Sorry, I'll stop now." justification. And you're _still_ whining that you're being treated unfairly.
You violated their Terms, plain and simple. They don't owe you a second chance or your data.
As a side note, surely a CS major knows they should keep backups of every thing. Better yet, shove your text/code files into git and have backups AND versioning.
They told me that my files are safe at first. However they still deleted my account with all my files in it
If so, who complained to digitalocean?
If not, your professor should be fired, because the assignment encouraged students to break the law. Forget DigitalOcean's TOS. Attacking a server without permission is a crime.
No one complained to digital ocean. The digital ocean told me that they detected the attack by their router.
I am not attack any other servers. What I attacked is the specific virtual server hosted by university of waterloo itself.
Another thing is they should not say that the files are safe in first place, and then destroy them afterward. Maybe this user trust them and wait for the files to submit his assignment.