DigitalOcean Raises $37.2M From Andreessen Horowitz to Take on AWS
techcrunch.com
techcrunch.com
* kernels lag terribly behind the distributions meaning you're wide open sometimes.
* can't resize or add storage
* no freebsd support or custom kernels
* VM availability problems. If you want to have another box, you aren't guaranteed to get one.
* no IPv6
* somewhat shonky security reputation.
* cant deliver to yahoo mail from their AMS2 IPs I've been given even after filling in numerous forms at yahoo.
Apart from that, they're the best hosts out there. I pick them over Linode, Hetzner and EC2 but not colo. Even at the price point they're at.
Then I can sleep/configure the rest of the system.
Been meaning to package this all up in an ansible playbook but I can't be bothered :(
I'd be using FreeBSD if they offered it. Much like OpenBSD it's a lot more pleasant for sysadmins!
Don't forget https://github.com/kickstarter/rack-attack as well though.
To be fair I'd just use FreeBSD which has a little better kernel architecture with respect to security.
Writing this playbook paid off already for the second installation of the box.
Restart ssh after editing sshd_conf.
If you're squeemish, run dropbear on another port so you can log into your machine in case you made a boo-boo configuring openssh.
Also, more resources for security settings:
https://benchmarks.cisecurity.org/downloads/multiform/index....
Give us your address so we can send you money.
Shameless plug: a small side project I did with my team at nodeSWAT [1]: CMify [2] - a web service to easily generate your ansible playbooks. Somewhat naive so far, if there is interest we'll extend it.
[1] http://nodeswat.com [2] https://cmify.com
Small thing but at least then it doesn't shout "Hey I'm a *nix box with remote login enabled"
I've always been installing denyhosts but I have not compared the two.
https://www.google.com/search?q=fail2ban+dos+bug
A better approach is something like pam_abl which is a pam module that will accomplish mostly the same thing but only for login attempts and without the crappy plain text log parsing.
PSA: If you just update the kernel using system tools within the instance, it'll still boot the old one. (At least it did few months ago.)
The grub (or other bootloader) and kernels that are installed inside the instance's disk image are silently ignored and the vm uses a kernel stored outside of your instance's image. You can select which kernel image you want to boot in the control panel. The problem is that the kernels available in there are updated very, very rarely. For popular distributions like Ubuntu they can lag several months, for others it can get up to, say, _two years_ [1].
Since digitalocean "doesn't support custom kernels" it appears that the only way to use something up to date (and stay secure) is to write a script that loads a custom kernel using kexec. :S
edit: The fact that they use kvm (and that kexec works) which means real visualization but can't boot user's kernels is just very, very weird. The only technical reason i can think of is that they can't manage to make it work with their control panel. If that's the reason, then it's very worrying. (The "right" way is easier to code and it's the solution that you'd think of first and it makes custom kernels a non-problem, but they picked one that both has obvious problems and is harder to setup, i can't think of a reason why.)
[1]: https://www.digitalocean.com/community/questions/how-can-i-b...
At this time we only support xen paravirtualization(PV) though, which almost, but not quite, all major distributions have. Notably we can't run 64-bit freebsd right now because they only have HVM support. I'd like to change that but it needs more testing first. Here is a partial list of distributions supporting xen: http://wiki.xen.org/wiki/DomU_Support_for_Xen Really any linux distribution with a modern kernel can be made to support it though as support has been in mainline for a long time now.
As is industry standard, I'm upgrading existing customers (e.g. they stay on the same price plan, but they get more resources) before I offer those new price plans to the general public. I have maybe... 1/3rd of my customers upgraded to the plan I promised several years back (that has more disk and less ram than the plan I am upgrading to now.)
A big part of the problem is that I made a huge business mistake a year ago that cost me most of the money I would have used for upgrades. But, I've got a few options on the table, one of which is just consulting for a while;
if I go with used hardware, I'm within $50K of having enough hardware to upgrade everyone to "competitive, but not great" pricing. - that's maybe 3 months of full-time contracting work. Completely reasonable. Of course, used hardware is a lot like 'technical debt' - pay me now or pay me later, but it might make sense, just to get the monkey off my back. (That, and dealing with hardware problems is part of my core skillset; I can probably eek more reliability out of used garbage than most companies can.)
I'm talking 2-3x that for new hardware, which is a lot less realistic without some sort of loan or lease, something I should look into, but eh. I am thinking that used hardware until I'm competitive, then start buying new hardware once I start getting new customers on board might be the best way to go. The company is vastly easier to run when it's slowly growing rather than slowly shrinking.
1. their original "inject kernel into OS and boot from it that way" architecture was designed that way on purpose, so that users could downgrade kernels out-of-band as a way to rescue a bad upgrade;
2. but now they've got thousands of droplets configured that way, so switching architectures to something sensible will require either A. forcibly installing grub on, and restarting, every one of their nodes (not something people expect out of a VPS provider), or B. coming up with some sort of glue that can manage both the nodes expecting an injected kernel, and nodes that want to boot on their own, and providing a way to transition your nodes from one to the other.
Basically, it's a mess. A bit like the problems Heroku had with its Alpine stack.
sudo ufw allow proto tcp from any to any port 22
sudo ufw enable
Then you can just edit /etc/ssh/sshd_config the same as you would on OpenBSD. sudo ufw allow from your.ip.addr to tcp port 22
Rest of the world doesnt know I have ssh up and if I'm ever in a hotel or something I can tunnel through my home or login to DO's panel and allow another ip sudo ufw limit ssh
sudo ufw enable
To automatically rate limit connections -- see https://wiki.archlinux.org/index.php/Uncomplicated_Firewall#... > There is a lot of functionality built into these
> utilities, iptables being the most popular nowadays, but
> they require a decent effort on behalf of the user to
> learn and understand them.
Is that a corner worth cutting?I'd rather use pf on BSD though.
Simple is being able to simply say "allow all outgoing traffic and incoming traffic should only be allowed for HTTP(S) and SSH" and being able to figure out how to do it by just invoking "ufw --help".
Maybe someday I'll learn about iptables, I'm sure it's going to be worth it, but for now ufw does the job for me.
> Maybe someday I'll learn about iptables
Hmm...
iptables -A INPUT -p tcp --dport 22 -j ALLOW
iptables -A INPUT -p tcp --dport 80 -j ALLOW
iptables -A INPUT -p tcp --dport 443 -j ALLOW
iptables -A INPUT -p icmp -j ALLOW
iptables -A INPUT -i eth0 -j DROP
So complicated...Indeed, it is. Even if you want to cargo cult that without understanding it, you might get bitten because running those commands again will not do what you expect, since they're not idempotent.
You will now reply telling me how to deal with this situation, for example if I want to now listen on a different port, or how I get FTP (or some other protocol that needs "-m state" to work. The need to do this proves that using iptables is more complicated that your example.
You should still understand iptables but you do not need to config everything manually.
* Can't add backups to an already provisioned node
* Undocumented "droplet limits" e.g. one day you'll click "Add Droplet" and it will say "You've reached your droplet limit, please contact support". They'll generally raise it after some basic security verification but it's a nasty shock since you don't find out about it until you need to provision a new Droplet, especially if you're in a hurry.
https://cloud.digitalocean.com/settings
The second is if a customer signs up using Paypal we restrict some of the larger sizes, this is done to minimize the amount of fraud we have to deal with.
Unfortunately we deal with a high amount of abusive and fraudulent signups so we've had to instate a lot of automated filters and other updates to the user experience. It really sucks, but without it we'd have a lot more fraud which would really just make the entire experience worse overall.
In either case opening up a ticket will get either issue resolved.
Sorry for the inconvenience but if anyone is good at fraud detection and wants to help us to continue to automate it and make it smarter, we are hiring =]
Thanks, Moisey
I suggest this because I've been using Digital Ocean for quite a while (several different accounts for different projects/ clients) and have never needed to look at that page.
The need for limits and additional verification makes complete sense, but it would be useful for it to be highlighted in advance (e.g. in an intro email or banner) so you can deal with it in advance of it becoming a problem.
This is a huge issue for us and we've wasted time with this.
It's not possible to shrink upsized instances like you can on Linode. On DO you can't even restore a snapshot or backup to a smaller instance size - you must rebuild from scratch.
I guess the right way to handle this is a configuration management tool, but this is a real pain since there is only local storage.
Yes, this is vital, but it's still not going to help you maintain existing data. A config management tool isn't going to fill out your logs, for example.
I've seen numerous complaints indicating that Digital Ocean abides no such policies.
http://digitalocean.uservoice.com/forums/136585-digitalocean...
Knowing first hand that other providers handle the exact same scenario with ample amounts of equitability informs my decision that there's a better way to go about it.
Effectively, it's the kind of policy that would allow me to jokingly refer competitors to becoming DO customers.
Anyone have any citations for case law where virtualized hosting falls under 512(c), and doesn't qualify for safe harbor under 512(a)?
512(a) would apply to, say, an ISP that stood between a system hosting allegedly infringing content and those accessing it, not to the owner of the physical system hosting that content who allowed a third party to control a VM on the physical system on which the content was hosted.
No, it doesn't.
The DMCA provides both a safe harbor for hosts against infringement liability (the take down notice procedure) and a safe harbor for hosts against any liability they might have for taking down content (the counter-notice procedure), but neither of these procedures are strictly mandatory, they just provide a liability shield for certain liabilities that the host may have had without them.
But most hosts have taken pains to assure that they have no liability in the latter case through terms of service, so there is little reason for them to be concerned with the counter-notice procedure.
If a host does not follow the entire OCILLA playbook in every case, unconditionally, across the board, the host no longer qualifies for any safe harbor whatsoever. Then it's open season on copyright violations. Think $400,000 per song style open season.
The real liability threat remains third parties, not customers, and disregarding the prescribed counter procedure is handing them the keys to the bank. If you see a host playing fast and loose with the rules, for example your content not being restored in 10 to 14 days after counter notice with no further action, it's time to go after their registered agent.
Under what grounds? Taking down your content isn't violating your copyright. If they lose their safe harbor status, some future copyright holder could sue them, but I don't see how you could.
The 512(c) safe harbor rules are clearly written in a transaction-specific manner rather than the way you describe, and every case I've seen on them has focussed on whether they were followed as relevant to the transaction and not addressed whether the host followed them "unconditionally, across the board". So, I think your conclusion is wrong.
https://vpsexperience.wordpress.com/
An odd experience, I would say.
I guess it could happen, but wow.. its like trying to get Beyonce derp face or whatever meme removed from the internet
(Full disclosure: My only relationship with Digital Ocean is having been offered a free month of hosting with them once. Never used it.)
Can you explain what you mean here? The blog owner appeared to be offended by the Googler's stance that he was taking in a public chatroom about Google policies so he blogged about it. How is that a creepy obsession?
But if true, I'm moving everything away to a more professional hosting provider. You don't just shut down a hosting account because of a single anonymous complaint. That's just a silly thing to waste your time with.
I also have a vegitable garden which we can most of our food from or preserve in other ways. :)
If I want a chicken that tastes just as good as the ones I raise I have to shell out $20+ for a 6lb whole chicken.. Crazy.. I get it for about $1/lb.
I have a massive vegetable garden but not enough to survive off completely as we're in a London suburb so we concentrate on growing the expensive stuff (and potatoes because once we planted them they just keep coming up every year).
Can't do chickens here - too many foxes.
"I wonder if anyone has ever tried to run a startup out of a cave..."
3.13 Subscribers may not use the Services in a manner that would violate the lawful privacy rights of any person, ... or embarrass, which shall be determined in DigitalOcean’s sole and absolute discretion.
So... if someone gets embarrassed by what you put up, DO just decides to take it down.
There are occasional weird situations like this that come up and I would love to handle every support request directly but unfortunately that's not possible.
We've had to scale the support team to support over 100,000 customers and we didn't get the right customer support director on board till about 2 months ago.
We are constantly looking to improve our service in all areas and Zach is on top of it to ensure that all of our customer support staff get more training in how to better respond to customers.
However, the promise that I make is that if any situation ever arises in any way shape or form with DigitalOcean please contact me directly - moisey --- a-t --- digital0cean - and I will be on top of it as soon as possible.
I hope that helps in response to this issue.
Thanks, Moisey
At any rate, I have no way of knowing about this issue. It's just curious that DO would put embarrassment as a ToS violation. All sorts of stuff embarrasses all sorts of people. Might as well just put up "DO reserves the right to terminate your services, at any time, without reason."
these people do not give a shit about the streisand effect. they are going after their money.
We try not to interpret the law as that is not our specialty of course, we are simply saying that we would like that customers use the service for a non-malicious purpose. But we're more than happy to open up a dialogue about this and make amendments if necessary.
Thanks!
In regards to embarrassment it's about the intention of the statement which is to not use the service for a malicious nature. But we're more than happy to open up a dialogue about this and see if there are any amendments to the terms that are a good idea.
We'll push on getting more of our public content into github so that customers can provide feedback and provide rewrites of the terms that they feel capture the sentiment but perhaps clarify those terms better.
I'm sure they will get that eventually. Maybe after they learn to scrub customer storage in every case (not just enough to sweep the issue under the rug) so that droplets aren't immediately compromised on termination.
In case that wasn't clear to you, DO puts their drive wear ahead of your data. There are still multiple endpoints in the API that will leak your data to other customers. They fix some cases of it every now and then, then revert without telling anyone once they see the impact on their SMART metrics. When sneak called them out they wrote an entirely fabricated blog post. That incident resulted in a published CVE in libcloud earlier this year but of course nobody gives a shit, throw more VC at them!
Even if you take the stance that his ability to speak freely should be defended (which I agree with) I suspect his behaviour here indicates there could be more to the story. Plus he sounds like the kind of customer I wouldn't want to have.
Businesses should be free to choose who they serve (subject to some restrictions around bias against classes of people).
It sure seems like the author went into the chatroom looking for a story, and got the THINNEST of all possible stories ("Random Google Developer Has Opinions") and, in an effort to turn it into real news, colored it in the most negative way possible. It is profoundly terrible journalism, and the motives behind it are so ugly. This is not something that we should endorse on Hacker News.
The only story of relevance here is that Digital Ocean has a line in its TOS about not allowing "harassment or embarrassment", and they will enforce it if you do indeed harass a guy.
I think you are missing the real relevance here; that DO will use their own discretion to determine if your content is worthy of dissemination. You're right, it was terrible journalism, and a thin story. So what of it? Why should DO concern themselves with the content that isn't breaking any laws? What, precisely, is "embarrassment"? It was a no-name blogger posting a non-story.
>This is not something that we should endorse on Hacker News.
The fact that you say this explains a lot about why you have your opinion on DO and how things should work, and why I have mine. If this story is getting upvoted, it's getting upvoted. There is no "we", unless you're trying to curate opinion and create an echo chamber.
Say, for example, that there's an article about a "scientific study", claiming some strong conclusion (e.g. "pig hair cures diabetes.") The article goes on to say that the study has one data-point and no control-group (which is to say, basically, that it's an anecdote.)
To still even consider the study's conclusion as possibly true is to privilege the hypothesis. You didn't have any facts before. You don't have any facts after. And yet, your default has switched from "assume pig hair has no special properties whatsoever" to "assume pig hair maybe has something with a vaguely-medicinal use in it." You've updated on zero information.
Just as much as publicizing such a "study", it's irresponsible to put such journalism--sophistry, really--in front of other people, where it could possibly infect their defaults. Not everyone catches these things. Most people only read the first paragraph or two of things, and come away with impressions. These impressions, especially in the case of really bad journalism, can be directly opposed to the impressions they should have taken.
If we are a community here, then we should want to help one-another avoid bad journalism, and more importantly, avoid becoming swayed by whatever the bad journalism purports to report. We don't all need to think the same thing--but supporting a story just on the basis that other people support it, leads to pig hair being "signal-boosted" into notoriety.
Or are they exercising editorial discretion?
All I was talking about is the meta-issue you brought up, of what HN as a community should or shouldn't "give air-time."
Getting ahead takes capital and i'm sure they're aware of what makes them inferior, you can't raise $37m without a good story on how you're going to use it to get ahead and win.
I have great hope for http://bigv.io but they're not quite there yet.
Having worked for some big hosts myself, i know how hard it can be to make changes once you have people using your platform. I suspect DO are in a similar situation and are looking to make a big leap forward with new growth leveraging their existing brand. I have no real evidence of this, but it feels like a sensible course of action.
No one likes giving up equity and taking money unless there is a damn good reason for it.
Normally in these situations, much as they do with DO already with disparate DC capabilities, you deploy infrastructure side-by-side and slowly port it over from one system to another. Developing the capabilities isn't really a big problem even if you build it versus buy as the total developer / administrator / server ratios on these sorts of companies are pretty favourable to massive automation.
I suspect they really do just want the money. Either than or they've short-sold themselves as a bargain host and now have trouble generating revenue and will lose too many customers if they crank prices so they're riding the investor's crack pipes via hype.
The latter is all too common unfortunately. One of the UK's "leading" hosts I did some consultancy for in the mid 00's actually relaunched with just under 50 CentOS servers with shared hosting/cPanel stuff on them but priced too low. They got customers but not enough to pay for the cage. Spent a couple of months moving their shit into a single 42U and consolidating their billing and provisioning system. They're still around now and can pay the bills. I did it for cash - I wouldn't want the equity myself.
Ramnode absolutely sucks. I can pull maybe 100k/sec off them if I'm lucky from UK in their US and NL data centres which is abysmal. Cancelled my account the day after opened it.
- The site doesn't look good on my Retina MacBook Pro, mainly due to the extensive use of low resolution images for things like gradients and text (I don't understand that at all).
- Only pricing is in GBP, it'd be nice to have something else as a reference (a little "roughly $16 USD" in brackets would be nice)
- Straight up asks for my full address and phone number, without stating a reason why they're necessary or how they're used
- Takes me to a payment page and asks for my credit card number on a plain looking page served with a Class 1 SSL certificate (no organization validation) and again, with no indication how it'll be used
I was actually looking to give it a try after filling the address fields and phone number with "Nopenopenope" but lost it at the (subjectively) dodgy looking payment page.
A redesign and some explanations on signup pages would do you a lot of good I think :)
I ran into that in connection with MIPSpace. Large swathes of DO IPs are blacklisted by MIPSpace, which impacts my deliverability for a small double opt-in hobby list.
- Digital Ocean says they can't get MIPSpace to remove IPs.
- MIPSpace will only deal with me if I can get DO to add rwhois/SWIP for my IP
- Digital Ocean doesn't offer that feature (of course).
So I'm somewhat stuck there. Not as though things are going to be any better elsewhere on another cloud service, I suppose, though I never had these issues at AWS. But moving back would triple the cost of running an equivalent mail server.
Hopefully some of the funding here can be used by DO to actually clean up their IPs and manage the issues with the less reasonable blacklists like MIPSpace - who doesn't send abuse notices, and seems pretty capricious, from what I'm reading. Since DO are in the business of renting IP addresses, it would be good if those IP addresses were not usually on some blacklist somewhere.
So while DO is saying no, I'm wondering if it's because they don't offer the space required to SWIP the ranges. In addition to not offering the size, it would incur additional administrative overhead.
Can't blame them.
Edit: definitely possible http://lowendtalk.com/discussion/12406/which-providers-provi...
So you shouldn't call MIPSpace stupid, thanks.
1. Dependency on ColdFusion. Seriously that product is dead, poorly maintained and powers the entire front end. That's scary. Even more scary than PHP written by outsources from Elbonia. They got hacked due to this.
2. Billing system is take then refund credit rather than billing afterwards.
3. From my location their latency and throughput sucked even in their EU DC despite being only 11 miles from my house.
Got a $20 credit for my trouble (good PR!), and then promptly moved on to a provider that actually supports my needs.
I've been (stupidly) running my website, VPN, and e-mail servers all on a single EC2 instance, mostly because I had a bunch of AWS credits. I got some Google Cloud credits, so decided to move it there. I then realized that I'm spending $60 a month on a single instance, which despite having "free" money, is stupid.
I split everything up into Docker containers, and run them on Droplets now. Sure, I pay $5/month now for each server, but that's fine. One of the e-mail servers is for my wedding; I'll turn it off when I don't need it anymore. The interface for bringing up new Droplets is simple and clean, and lets me do exactly what I need to, no more and no less.
If you look at AWS or Google Cloud, there are so many available services that it can be daunting to get simple things going. I mean, it's not that bad, but once you've seen DO's interface, you realize how unnecessary a lot of it is.
I would still likely use AWS/GC for cases where I need to respond to changing load needs, which incidentally, is exactly what you're supposed to use it for. A DO + AWS hybrid infrastructure would be most ideal IMHO.
Its been a really great and easy testbed where I can test out new things I am learning. Now I can get a VPS running linux serving up webpages with apache in about 20 min. Add in the great price and I have been hooked for over a year.
The reason I finally settled with DigitalOcean after trying AWS, GC, RackSpace and WebFaction etc, is it's stupidly simple interface. I start things with just a few clicks and few words typed and then it's just like I am in my good old Ubuntu terminal.
Though I run my low volume email server, VPN, proxy, ownCloud on one droplet and it works just fine - no load, no issues.
IPv6 in Q4 2012: https://www.digitalocean.com/community/questions/is-ipv6-ava...
Ability to boot own kernel ("2-3 weeks from Feb 2013"): https://digitalocean.uservoice.com/forums/136585-digital-oce...
We ran into this problem because we were used to our development cycle that we had in 2012, but in 2013 our growth really took off and we spent most of our time working on scaling challenges.
That unfortunately pushed us back on a lot of different timelines. Now that we've grown the company from 5 people to over 50 and with this latest round we're finally catching up and able to move things forward at a better pace.
We are reviewing and reprioritizing our product roadmap this weekend and next and will be providing more updated timelines and also issuing more updates if we fall behind on the new estimates.
Thanks, Moisey
not sure if digital ocean has customers in the $20k+/month range, but they are by far the least demanding.
pretty incredible isn't it?
This is not restricted to web hosting, but common human behavior.
I've freelanced as a web dev and wedding photographer in the past. Low paying clients typically demand much more than higher paying ones.
Good luck anyways.
For smaller numbers of instances it's true that you can spawn whatever you want and use them for whatever you want, as long as you pay the stated rates. But for larger numbers of instances you do actually have to tell Amazon what you want them for, and your requested use-case "will be considered". You can't just spin up 1000 instances and pay the stated rate without getting prior authorization; the API will block new instances after a certain point. Here are the default instance limits: http://aws.amazon.com/ec2/faqs/#How_many_instances_can_I_run...
Second, it's integrated. Which, to me at least, feels much more natural than AWS where you rent a virtual server, and then a database separately, persistent storage separately... Because it's integrated, it's also simple.
And they have a datacentre* in Amsterdam. Even two of them, right in the heart of the European Internet. That means latency to their servers is not noticeable in much of the EU.
* Yes, yes, probably more like a cage or whatever they rent.
or
hello network hdd
Due to downvotes, I guess I better explain what I mean: Basically, EC2 provides instances where "if you restart your server you lose your data". You don't use those when that would be a problem for you, you use EBS backed instances which do not have this problem. Or you do it some other way. Point being, this is technically true but it's not really a problem in practice.
The double taxation reference refers to it being a somewhat common misconception among people that have taken a business class before that US corporations are "double taxed". IE, corporate profits are taxed, then your personal income is taxed. This is technically true but does not actually matter because you pay yourself a salary (which is taxed as income), but this is deducted as an expense from corporate income (thus not double taxed).
Point being--it's the same FUD.
BTW, when I invest in a corporation, I do get double taxed. The profits are taxed at the highest possible income tax rate, then I pay 15% tax on the distribution of profits.
Of course if I work for that corporation, I opt to take the "profits" as a bonus. I pay all the taxes in that case, but at least there isn't double taxation.
For data that must be stored, I can use a EBS, or a database instance.
Like the grand-parent said, you pick what makes sense. Saying that ephemeral storage is a bad thing would be true if that were all they offered, but it isn't, and it ephemeral images are sometimes preferred.
That sentence makes no sense to people with no AWS experience. But if you give someone with Linux experience secure shell access to a DigitalOcean server they can hit the ground running.
It's not rocket science:
instance = virtual server ("droplet" in DO speak)
terminate = shut down
ephemeral store = local disk
An EC2 instance is just a virtual server so anyone who knows Linux, Windows, BSD or even Solaris can "hit the ground running" there too.
That being said, do they dump your instance if they reboot the physical server? I was under the impression that "Oh we want to upgrade they hypervisor kernel, your instance is toast", was fairgame/default on Amazon.
Nope. In most cases, you get two weeks warning before a physical host is decommissioned. I've gotten as little as 24 hours (guessing it was a more significant than usual hardware issue).
When that happens, you can just stop the instance, then start it again. That moves it onto a new physical host. If you don't do it in the 14 days, Amazon does it automatically. No loss of data, and just a few minutes of downtime if your startup scripts are OK.
Amazon should really advertise this, if that is the case. I was under the impression that Amazon couldn't be relied on as a VPS.
As I said above - the terminology can get hairy pretty fast. It's valuable to take stock of what you really need persisted, and what use can be made of 'scratch disks'. Local ephemerals are fast and cheap (included in the price of any instance). They come with the operational overhead of needing to rsync data off of them yourself if you want to retire that instance however.
So no, its not FUD in that case at all.
You're right. But you're not going to avoid the stock market (where you might get paid in dividends) because you want to avoid double taxation. However, when forming a company for the first time, you'll hear double taxation cited as a reason you might not want to form a corporation. This is stupid because you're not going to pay yourself in dividends. Of course there are many reasons you might choose one business form over another -- I'm just saying that double taxation really isn't one of them.
Likewise, if you are deciding between digital ocean and AWS -- there are many reasons why you might want to go with one over the other. One of the reasons is not because you lose all your data when you restart a machine on AWS. I mean, look, I'm considering giving DO a shot for various reasons, but AWS losing my data because of some oversight in their service that DO has fundamentally engineered around isn't one of them.
In both cases, I'm not saying one is better than the other -- all i'm saying is some distinctions are subtly stupid to the point of being manipulative. As in FUD. That's my full thought process on this matter, I don't think I've got anything past that, haha
A company that has $10MM in revenue, and $10MM in salary expense will pay zero corporate income tax.
Up to a limit, your salary as owner is deductible to the corporation. Generally, the "safe" limit is usually the current SSI maximum wage. Beyond that, the IRS is very likely to re-characterize wages paid to owners as dividends. While this actually results in a lower (direct) tax to the owner, it usually results in higher taxes to the corporation, plus penalties and back interest.
Note that this is generally true for LLCs, S-Corps, and C-Corps, though the precise rules differ based on the type of entity. You'll definitely want to talk to a lawyer or accountant.
Unless I'm missing something with AWS, what oversight in their system causes you to lose data? They are quite upfront and transparent that your data does not stick around unless you use EBS.
In summary: typical pass-through entity distributions are typically taxed as self-employment income and subject to the SET which attempts to recover the missing employer's half of tax payments. You cannot avoid all employer's half of taxes by taking them as distributions, and whomever told you that has misled you.
Now, what you might actually be thinking here, and would be correct, is that for those who earn less than a certain income (which would place them in the top tax bracket), the effect of applying all of those payments as self-employment income generally results in a lower tax rate than the corporate tax rate, and allows for deductions that companies may not have available to them.
What you're talking about does not apply to LLCs, it is a special situation only related to S-Corps. Generally speaking, pass-throughs such as LLCs all distributions are taxed as self-employment wages, except under certain conditions.
They are a VPS. They do bill hourly, which makes them somewhat unique. They were early to offer SSDs. Their pricing is great.
I don't want the "cloud". I want a really good VPS. Digital Ocean fits that bill.
And in that vein, wouldn't the winner in each area just be the one who bought their hardware the most recently? Instructions/dollar are still increasing on each CPU generation, but it'll take more than one generation for each machine to pay itself off. So, whoever is closest to the current generation pays the least per instruction, and can charge the least.
Or, maybe it's memory/bandwidth, which are mostly commodity, but slightly bottlenecked by the hardware (e.g, max on a motherboard, NIC throughput). Maybe the combination of prices in cpu, memory, and bandwidth leave enough variation between competitors to keep the field a little open? I donno.
[1] Modulo concerns about their ssh key management. I haven't looked after the last news ping on it.
Well, I don't think it's like aircraft or auto leasing. More like apartment or office leasing -- there's also a property management, maintenance, and operation dimension.
You're not just paying for hardware in a rack. You're paying for electricity, cooling, fire prevention, connectivity, and some level of uptime. i.e. You're paying for not having to worry about a bunch of stuff, so you can focus on your core business problems.
Even with standardized management software, at some point a human needs to go into a cage, or deal with the backhoe emergency. (OK, unless someday Amazon drones are deployed in data centers, instead of doing residential delivery. :))
My main issue is that I would like a hardening script, instead of having to go through each new one I spin up and lock it down.
A while ago, I started giving out VPSs to friends of mine to get them to stop making excuses about why they can't code.
Digital ocean, at $5/mo, has made this really easy :)
* Set up a static blog engine like Pelican [0]
* Learn Ansible [1]
* Try a distro you haven't used before
[0]: getpelican.com
[1]: http://sendgrid.com/blog/ansible-and-digital-ocean/ (although this really doesn't show off the power of something like Ansible)
OpenBSD -- the world's simplest and most secure Unix-like OS. Creator of the world's most used SSH implementation OpenSSH, the world's most elegant firewall PF, and the world's most elegant mail server OpenSMTPD. OpenBSD -- the cleanest kernel, the cleanest userland and the cleanest configuration syntax.
https://digitalocean.uservoice.com/forums/136585-digital-oce...
I won't top it up again but as long as you know they're somewhat dishonest and reckless with customer data then it's okay to use for stupid stuff like distributed builds or something (provided the source code you're building isn't private/secret/proprietary).
The lies are still up on their blog:
"At no time was customer data "leaked" between accounts. This would require that a user not scrub their volume after destroying their server; in this instance data would be recoverable and should be considered not sensitive."
For a long time, if you deleted a DO virtual machine, it would not delete your data by default, so that the next customer would receive it on the block device to be recovered.
When I pointed this out to them, after it caused me a few thousand USD in credits I had to issue to my customer (as I remediated DO leaking my customer's data (through my use of the service)), they maintained "there's no leak because we give you a checkbox".
There is absolutely no circumstance, checkbox or no, in which delivering my data on disk to another customer is okay.
After I made a huge stink about it, it ended up at the top of HN, and they switched to a sane default (scrubbing disks after a user deletes a VM). It shouldn't even be an option, but there it is.
Despite all of this, though, they continued to lie about the root cause: they were careless with their customers' data and trust.
It looks like they've hired some people who aren't dicks and have since updated the blog post with sanity. Nice to see, but still: be mindful of how these people conduct themselves.
http://vpsexperience.wordpress.com/2014/01/05/digital-ocean-...
Now after adding getmail to back up gmail I am now wondering what more I can do with it.
And it's not for Debian only, I'm running it on Arch by following this tutorial.
https://www.digitalocean.com/community/articles/how-to-set-u...
I had used it to setup a test server and had no issues -- FYI, the date on the article is today, but the original article has been available for a few months so perhaps the article has been updated.
It's like comparing a harddisk manufacturer to Apple.
Even EC2 is barely an overlap, since EC2 is a computation unit in the convenient form of a (very ephemeral) virtual server, not the virtual equivalent of an actual, permanent server. (And you're going to be in a world of hurt if you use them like that.)
The main place where I could see this being appealing would be complex analytic jobs (since they're more CPU-intensive), but even so, if on 512MB nodes it has to spill to disk because there isn't enough RAM (or transmit a bunch of data across the network because it split the job over two nodes) and on a bigger machine it didn't need to, you probably would have been better off with the bigger machine.
The entire site had to be created again from backups on a different VPS provider. Surely their system should be able to migrate any droplets off failing nodes automatically, I mean hardware failures happen right?
What else...
What do you mean? Actually private network did not exist on DO until recently and it's been on Linode for a long time.
To add another. 6) Linode offers IPv6, while DO says it's coming "soon"[2] (and has been saying that for well over a year).
[0] https://www.digitalocean.com/company/blog/introducing-privat...
[1] https://blog.linode.com/2008/03/14/private-back-end-network-...
[2] https://www.digitalocean.com/community/questions/is-ipv6-ava...
Basically following:
1. No public IP on each machine by default 2. Security settings managed through web UI and apply to linodes from UI.
DO had lots of hiccups with it's networking when I tried them (though was over a year ago so ymmv).
Everything I have on Linode earns me money in one way or another so they pay for themselves, I currently have 3 nodes for a total of $60 bucks a month, DO I could do the same for $15 but really $45 a month is nothing compared to the cost of a machine going down even briefly (even if it takes me an hour to fix, I bill more than that).
For me Linode hits the sweetspot of price/reliability.
They have deliberately withheld information from customers not once, but twice during critical security incidents.
Looking at the feedback from their user base, and even rom my own experience, different storage options would be way more useful than IPv6 or even load balancing.
I finally got an answer last night[2]
1. http://digitalocean.uservoice.com/forums/136585-digital-ocea... 2. https://twitter.com/jedgar/status/441314391301296128
Please be aware that some internet users only have native IPv6 connectivity, and that IPv4 addresses are becoming increasingly scarce, especially if you are setting up thousands if not millions of virtual machines, like DO.
No Pooled Bandwidth Networking and Route, as well as capacity need some work. Linode is much better in this regards. No Custom Kernels IPs Problem. Still no deploy to different physical hardware by default. No Private Networking on most of its DC.
And possibly many other small things i didn't mention. To me most of those are deal breaker. And my problems with them is that are not fixing or improving these problem quickly enough.
While Linode's SSD are quickly approaching, and has none of those drawbacks.
What about actual security too?
Maybe they'll stop the censorship if they want to be a real VPS player? (https://vpsexperience.wordpress.com/)
Oh, and I wish they'd use real industry terms, not stuff like 'Droplet'. That's just stupid.
Right now, anyone at all who aren't GoDaddy or Network Solutions are better than Digital Ocean. You get what you pay for (AWS excepted, who are price gouging).
Full disclosure: Happy Linode customer.
Here's some dissenting opinions about them. Half of them have some sort of merit.
Disclosure: I have a vested interest in their direct competitor.
Seriously, man? You point out some valid things but this post doesn't really serve a purpose.
So what if I use Linode? I don't work for them. I use two other providers as well. My 'vested interest' in them is limited to my VPS there running. I don't get a discount for pointing out DO sucks and Linode don't ban me if I speak ill of someone they like.
PS. Is a VPS host really a 'cloud hosting provider'? That term makes me think of overpriced individual services that aren't a self contained system, like AWS/EBS/their hosted databases.
I've never been cracked, and chances are I know/care more about security than the average user here. Either you've misidentified me or you're lying about me.
The question is, do you really make money on $5 a month servers? I don't know if they actually are. The costs are for support people and now large numbers of engineers.
The thing is with that much funding it doesn't really matter if their income is greater than expenses. They can continue for at least another few years regardless. During that time sane people who just need a VPS will take advantage of it.
My recommendation for DO's business model is simply to set a precedent and make it a policy that if you pay only $5 then you don't get any kind of free support. That is the only real cost that sticks. So I suggest having a few different monthly support options available starting at zero support for $0 and up. That is the main business issue a provider like this has is the conflict between the desire to provide good support and the need to keep unit costs low. And the solution is to separate support out. The main challenge to doing that is sort of a cultural/expectations/marketing issue.
The reason we raised our seed round is that our growth began to outstrip our ability to acquire hardware and grow the business at the rate at which our customers were spinning up more droplets.
The second round that we raised was again for the same reason. Growth has been completely unbelievable and we are humbled by the support that the community has given us. We thought that our initial Seed round would certainly be enough to cover our growth but quickly saw that growth was actually increasing so we made the decision to raise a second round in a rather short period of time.
We were immediately impressed by Peter Levine's knowledge of the space and we are super excited about having a16z on board as our partners. This round has certainly provided ample funding for us to continue to expand not worry that our growth is going to outstrip our ability to finance it.
Thanks, Moisey
I spent seven happy years working remotely as a system administrator, for a company listed in some of these comments, and wonder if this is something you've ever considered?
I know that payment issues and similar might complicate things, but I'm surprised there seem to be essentially zero remote-working positions advertised for a company that will have round-the-world clients/users/customers. (i.e. You're liable to get issues, tickets, and monitoring alerts round the clock.)
I'm really excited to see these dudes take on AWS with a higher-level and more performant platform.
I think my initial dislike is due to it being changed, but there are tons of minor usability issues that I never noticed on their old website.
I'm happy to see a view for new articles in the tutorials database [0], but at the moment it doesn't make any sense. When I hit it just now, an article from 11 minutes ago is above an article from 1 minute ago. Not only that, an article on the 52nd page says "less than a minute ago". From clicking around, it seems like some process has touched every article recently and all those times, and how they are sorted, are meaningless. Also, at the moment the new and tending view gives the exact same outcome, at least for the first page.
Must have been very recent; I was on it just the other day with the old design.
At Amazon's scale, you can make it up on volume.
Digital Ocean is like the place with a bunch of servers in the garage. Yes, its cheap. No, I would not trust it to run my business.
I'm very interested to see how they think they can compete with AWS, considering Amazon's cost to acquire equipment and their AWS software engineering team.
I don't see the problem with this. Either give your EC2 instance in your VPC a dedicated public IP and configure the security group to disallow all inbound connections, or use a public IP that routes all traffic for your VPC and again, secure it with a security group.
We do this right now with our environment, as our application is heavily EC2<->S3 dependent. It works without issue.
I realize many people probably don't have this particular need, however, I don't think it's completely unreasonable. Instead, I'm just mounting an EBS volume on an instance and running nginx to serve files.
Which you can still do, by using bucket policies/permissions in S3 (specifically EC2 IAM roles in this scenario).
I think we're arguing different use cases though. If your content is only used or getting served from one machine, EBS volumes. If you need to have it served to the world, available to multiple instances, etc, S3.
I could just use S3 from Linode but that would result more paid bandwidth and increased latency.
I like them and they are cheap but if your server fails then it can take hours to days getting back online.
vs 2 minutes on linode
Only their billing is a hot mess, mostly because they think it works and their customers are wrongly entering the CC #. For 4 months now, same problem and they have off-shore support that reads scripted answers. They just read the closest answer related to billing.