DigitalOcean now supports FreeBSD
digitalocean.com
digitalocean.com
Before, when a company provided Xen or Kvm, you generally would get to have low-level access such as the ability to virtually connect to a serial port or vnc session of your box as it booted. You also, typically, could provide your own ISO images.
Even if you couldn't provide your own iso, being able to interact with the VPS in the above way would allow you to use one of the provided disks and then bootstrap the install of another (this is how I installed gentoo on many providers that didn't "support" it)
DO's stance that you must use one of their images, you can't upload your own, and you can't even use your own kernel (I'm not kidding! If you "sudo apt-get update" to get a new kernel security update and reboot, DO will IGNORE your shiny new kernel because they hardcode the kernel as one they control. See [0]).
This is terrible. We shouldn't be happy that they're adding FreeBSD to the list of images they allow you to use, we should be showing, with our wallets, that their restrictive setup that doesn't allow you to touch anything outside of their tiny garden and exposes you to security issues is unacceptable. We should be using other providers, like Linode, AWS, and GCE, all of which allow bringing your own image in some form.
[0]: https://digitalocean.uservoice.com/forums/136585-digital-oce...
They're still in early stages though, I'm sure this is in the pipeline.
I would not call Digital Ocean all that early. This has been an issue for years.
There's a market for everything. You don't understand my use case. My use case is "I want to click a button and then I want to be able to `apt-get install what-i-want` and then it should work. I don't even care whether it's Debian or Ubuntu, as long as it has apt-get because that's all I understand.
Granted, maybe I shouldn't be running VPSes at all but hey, it works, and I bet DO has many customers like me.
If you want to do such low-level things as upgrade kernels, then maybe DO's one-click-and-poof-you're-running is less important to you than some other features and DO isn't the best option for you.
DO is well know, judging by the fact that I know of it and I don't know a lot about VPS business. The fact that you and many of their customers want easy to configure VPS doesn't preclude them from offering a more configurable option for other users where you are able to install whatever kernel you want. Use more imagination and less microwaves.
It's remarkable that you start your sentence with "before". As a prgmr.com user, I can still get an out-of-the-band console and run my own kernel without any fanfare. (no affiliation at all, just a happy user)
Not sure if the same applies to CentOS.
The best solution is to have maintainers of the OS prepare cloud distributions. Many already do for AWS or OpenStack. Our own 'cperciva is responsible for EC2-compatible version of FreeBSD.
Until this becomes a standard, there's nothing wrong with partial solutions. I created a FreeBSD droplet right away.
Disk performance is also lacking in comparison to the ubuntu droplet as shown in the pastebin. Could just be because everyone's spinning up fbsd boxes on this host? :)
If you wish to have higher disk speeds, but not use backups, we recommend for you to remount your disk with journaling. https://www.freebsd.org/doc/en/articles/gjournal-desktop/con...
The parent link to gjournal is weird too, since gjournal is not the same as softupdates w/journaling (SU+J). It makes me wonder if they actually disabled softupdates too.
I found a random post[1] about issues (unmapped io?) running i386 freebsd with su+j in virtualbox (apparently a virtualbox bug[2]).
[1]: https://forums.freebsd.org/threads/freebsd-10-i386-data-corr...
[2]: https://lists.freebsd.org/pipermail/freebsd-current/2013-Nov...
What else has DO disabled and/or modified from a vanilla install?
Shouldn't this make it much faster as the FS no longer maintains a journal?
console="vidconsole,comconsole" autoboot_delay="10" console="comconsole,vidconsole" autoboot_delay="1"
Second console actually disables access from web console access, which is fatal.
Autoboot is not critical, although default to 3 sec should work much better for opportunity to change boot options from web console.
DO have screwed something up with their configuration if they need to make so many changes to make it work. No other VPS provider I have used that support FreeBSD (or OpenBSD for that matter) require any changes to the default install.
After performing some tests[2] I figure out that the problem was not FreeBSD per se, but the FreeBSD deployment on the specific virtual server... I think that *BSDs should be avoided because they tend to be a lot slower than linux deployments on virtual machines.
Many virtualisation providers don't support it properly, but "should be avoided because my suppliers are stupid" is a terrible plan.
16384+0 records in
16384+0 records out
1073741824 bytes transferred in 57.605991 secs (18639412 bytes/sec)
0.023u 6.128s 0:57.61 10.6% 25+172k 7+81916io 3pf+0w
> sudo mount -o nosync -u /
> mount
/dev/gpt/rootfs on / (ufs, local, soft-updates)
devfs on /dev (devfs, local, multilabel)
> time dd if=/dev/zero of=/tmp/test bs=64k count=16k
16384+0 records in
16384+0 records out
1073741824 bytes transferred in 5.135908 secs (209065631 bytes/sec)
0.016u 2.274s 0:05.16 44.1% 24+169k 8+8193io 0pf+0w
Nice work Digital Ocean, love the way you folks keep pushing forward. Need some tutorials written?
[0] https://www.digitalocean.com/community/tags/freebsd?primary_... [1] https://www.digitalocean.com/community/get-paid-to-write
After reading the tut on HN the day before on how to be your own vpn provider with openbsd [1] I started to search for a tutorial that was either openbsd or freebsd with softether without much luck. I was about to do an instance of debian & softether.
Perhaps my comment would be better served in another way. I'm new at this and have no idea what I'm doing. :) How can I go about from setting a vpn server with a webpage for paying customers?
I'm looking at it more like a learning experience than to make it into a business, but if it works great. Could you or someone point me into the right direction into what needs to be read for each step of the way? I have very little linux experience, non in bsd and a little in python.
Thanks in advance.
The more comfortable people are with tools like DTrace, the better they will be able to write and use software.
- If you use Dtrace to troubleshoot a problem it's way beyond your scope of knowledge as a web developer. Dtrace is too deep and very specific to certain problems that you will never see because your regular nginx + php works fine in all cases.
- Not everyone wants and should be good at everything.
Just be good at what your doing well, I'm not saying that one shouldn't be curious but Dtrace isn't "an excuse" to install *BSD as a web dev.
DTrace is not hard, it's essential; and it's significantly easier, than say, awk, which is another crucial tool.
I think only Solaris has full support?
And DTrace in particular is really, really easy to use (the Linux alternatives, not so much).
Other than Dtrace... Tools like dtruss & co are not as clean as strace, that's the feeling I've got when I had to trace some calls.
I dunno how useful that is for web devs, but as a C programmer and perpetual tinkerer - FreeBSD suits my needs very nicely.
My prior post wasn't written as a statement of exclusivity, simply that I prefer the way freebsd does it.
The /proc/sys/ pseudo-filesystem interface has the advantage that it's discoverable. The sysctl(2) interface requires userspace to have knowledge of a swag of hardcoded ID numbers identifying each node in the sysctl tree.
Compare that to the freebsd man page [1]
[0] http://man7.org/linux/man-pages/man2/sysctl.2.html#NOTES
[1] https://www.freebsd.org/cgi/man.cgi?query=sysctl&sektion=3&m...
My point is that when you call write(2) under Linux on a file descriptor derived from opening a /proc/sys pseudo-file you are talking directly to the kernel code responsible for updating the sysctl variables in the same way as you are when you call sysctl(2) under FreeBSD.
The /proc/sys files aren't real files - they're just a way of representing the sysctl variables in the existing file namespace.
- I want to have a stable base O/S to which I can always easily return.
- I want to be able to customize installed packages in an easily scalable way.
- I want a server O/S to be simple to maintain, relative to Windows or Solaris.
- I want the goddamned documentation installed.
During development it's difficult to get RHEL or Ubuntu back to a known-good set of base packages without fiddling a lot with the package manager. It's better nowadays with package groups and autoremoval supported in both yum and APT, but with FreeBSD, you can always punt, do "pkg delete -a && rm -rf /usr/local" (or "pkg_delete" in the before time), and start over. The base configuration is also pretty simple and centralized, with most of what you need in /etc/rc.conf or /etc/periodic.conf.
pkgng + poudriere + a suitable web server makes custom package management really, really easy. I haven't tackled Spacewalk or similar tools for Linux, but even building locally customized versions of packages on RHEL or Ubuntu is a moderately complicated process compared to the FreeBSD Ports Tree. On RHEL or Ubuntu, you typically have to install the developer tools, hunt down the source RPMs/DEBs, edit the package definition, run rpmbuild/debuild, and install the resulting RPM. Compare that to the FreeBSD Ports Tree, where you run one command to download/update your copy of the package definitions, add whatever package-specific knobs you need to /etc/make.conf, and run "cd /usr/ports/category/packagename && make install" (the compilers and everything come built into the base system).
I'm not going to start an argument about the relative merits of init systems, as systemd (Linux), SMF (Solaris), and SCM (Windows) all have their merits, but I personally like the simplicity of configuring everything through /etc/rc.conf on FreeBSD. It's definitely old school, but then I cut my teeth on NeXTSTEP, SunOS 4, and Slackware Linux, so rc-style init scripts feel pretty natural to me.
As for documentation, I cannot tell you how many times I've wanted to run "man something" only to find out I need to install the -doc package. (Also, I cannot tell you how many times I've wanted to compile something, only to find out I need to install the -dev package.) Compared to Linux, FreeBSD has superior documentation. Even kernel bits get manual pages, and not just syscalls in section 2, but kernel interfaces and modules in section 4.
Of course I use both FreeBSD and Linux to great effect at home and at work, as well as Windows and Solaris. I just _like_ FreeBSD better.
That's the real reason. Everything else is rationalization added later.
(Don't get me wrong, I've also started on Slackware. But sometimes you need to break old habits to learn something new.)
Nitpick, but on Debian/Ubuntu this is a lot more simple than you make it sound:
apt-get source xxx # download the source package for 'xxx'
apt-get build-dep xxx # install everything needed to build it* PF (default on OpenBSD, a fork exists on FreeBSD) configuration is way more human-readable than iptables. Makes a lot easier to create custom complex rulesets.
* Documentation is much cleaner on FreeBSD (or OpenBSD) compared to GNU/Linux. Again helps you deploy complex solutions easily.
* The upgrade process (using ports or pkg) is well documented, easy to execute[1].
* ZFS makes FreeBSD a very solid file server
So, other than specific software, a clean approach on how start/stop services, where goes what, etc. I don't see any other reason for someone to switch from Linux to BSD.
However, given my experience ruby (I'm a ruby programmer) under-performs on FreeBSD VPSs compared to Linux VPSs while on bare metal doesn't. There are reports citing NetBSD as fastest ruby bare-metal OS. But again, differences shouldn't be all that much between BSD and Linux deployments in bare metal to justify a switch on VPSs though, if deploy ruby apps, I'd say stick with Linux.
[1] Hm. It's easy to execute if you are not afraid to read some extra documentation. But once you get the hand of it, it's really a breeze, never had serious issues with FreeBSD in ~3 years.
+ Jails
+ Capsicum [1]
+ Netmap [2]
+ Most performing network stack
+ Resource Management (pretty low memory usage)
+ The userspace tools come with the source (no GNU/Linux duality)
+ Clang/LLVM as default compiler stack
[1] - https://www.freebsd.org/cgi/man.cgi?query=capsicum&sektion=4
[2] - https://www.freebsd.org/cgi/man.cgi?query=netmap&sektion=4
A FreeBSD jail is a like a lightweight virtual machine, and is very similar to a Docker container in Linux (though it has been around for about a decade longer than Docker). It provides isolation for processes etc., but uses less resources than a full virtual machine. It is limited in that it has to be the same operating system as the host.
This is a pretty good overview: https://en.wikipedia.org/wiki/Operating-system-level_virtual...
Processes in the jail will only see network interfaces and other devices that have been explicitly exposed to the jail.
As others have said, it's like a vm with no virtualization overhead. You can set up jails with the entire Freebsd fs hierarchy so it runs like another host with its own users. Note that even the root user in a jail is not the same as the real root user. You can then use pkg to install packages within the jail too.
I use ezjail, btw.
I wonder if we'll now see additional storage addressed soon?
[1] https://digitalocean.uservoice.com/forums/136585-digitalocea...
Edit: I've had this theme bookmarked for ages, now might be the time to build it! http://daemon-notes.com/articles/desktop/example
"Built for developers" => can't use developer's favorite OS. :(
[1]: https://digitalocean.uservoice.com/forums/136585-digitalocea...
[2]: https://www.digitalocean.com/assets/video/create-e68d7b3c.we...
There are also other providers that support *BSD and people still requested it on DO. Why can't I ask for Arch?
[1]: http://w3techs.com/technologies/details/os-unix/all/all
You're right, we dropped the ball on UserVoice. There aren't any excuses to be made. I know it's a lot to ask, but please trust that going forward we will be much more transparent through UserVoice & elsewhere. We'll also be much more intentional in communicating our priorities through that medium, as this seems to be at the root of the concern about missing deadlines.
Again, no excuses, we're sorry we let you down, and we're going to get it right going forward.
Cheers!
I'm a DO customer, and while you've never let me down, I'll be paying attention now that you've given your word.
I think I speak for a lot of DO users who have to rely on AWS/Linode for larger clients that we'd move more infrastructure over to larger plans if we could just get better ops timelines. Your support for servers has been nothing short of great in my experience, but no timelines and no communication on stuff as important as retaining IPs and uploading custom ISOs (both available on cheap $5 VPS providers that are nobodies on LowEndBox) is really frustrating.
I noticed since few month back, if you destroy your droplet and create fresh droplet even after few days, you will get the same IP. Only in same DC though.
Maybe some sort of temporary policy while they're working on proper IP retainer.
I need to set up a nginx -> nodejs server for a project soon. Given I have set up a number of linux servers without trouble, how much of a struggle would it be to just use BSD for this new project? Would it be worth holding off and just messing about in a VM, or would my linux experience just transfer directly to setting up on FreeBSD?
We've prepared tutorials that can help you get started with the basics: https://www.digitalocean.com/community/tags/freebsd
Is this alternative method another SaaS with a different API and performance characteristics? That takes time as well, in addition to the vendor lock-in. BTW, stacking abstraction x infinity is what causes systems to be bloated, unreliable security risks. Time spent gaining a greater understand of components on layers below the level of the stack you're operating on is time well spent, you'll be a better developer for it.
While similar to other open source unix-like operating systems, it’s unique in that the development of both its kernel and user space utilities are managed by the same core team, ensuring consistent development standards across the project.
Wouldn't it be Linux that would be unique in that they don't do this? Solaris, AIX, HP-UX, all the BSDs, Mac OS X (which is certified Unix) does this as well. Correct me if I'm wrong here.None of the OS's you listed are open source.
The second part of the statement, the way I read it, is comparing FreeBSD to DigitalOcean's current offerings - Linux. Keep in mind the post is for someone that's already using DO's services, which is a person who has only ever used Linux on their platform.
> While similar to other open source unix-like operating systems, it’s unique in that the development of both its kernel and user space utilities are managed by the same core team, ensuring consistent development standards across the project.
I managed to get an instance running without too much trouble.
(I do not work for vultr, or affiliated in any way).
Also wondering how reliable Vultr's been for you guys.
EDIT: Should add that you do not get a complete /64, but 16 addresses from a /64. Probably in a private VLAN or something.
"IPv6 addresses are 128 bits long, compared to 32 bits long for IPv4. In other words, IPv6 addresses are 296 times more numerous than IPv4 addresses."
IPv6 addresses are actually 2^128/2^32 or 7.9e+28 times more numerous than IPv4, which would strengthen the argument that it's hard to be "wasteful" with them in the way described.
"FreeBSD droplets do allow you to customize your kernel. Unlike other droplets these boot from the kernel within their filesystem. This is the reason that FreeBSD is not available in NYC1, NYC2, and AMS1 as these regions do not yet support this option."
Thank you very very much for supporting FreeBSD!
edit: after actually reading TFA, it seems unlikely. Well, it seems like Dragonfly is most likely, if any others.
https://www.freebsd.org/doc/handbook/carp.html
My use cases so far haven't involved CARP but I'd like to start experimenting with that!
1: http://www.rootbsd.net 2: http://www.filemedia.de 3: http://www.lunanode.com
Compile your own kernels, your own world, and they are always on hand for assistance for things that you need help with.
I've been a happy customer for a number of years.
EDIT: Anyone cares to explain downvotes?
P.S. Hyper-V will let me go as low as 32-MB RAM, so thanks to you I'm keen to try out different operating system installs (and workloads) in low-memory environments.
P.P.S. Upvoted parent - I think the parent comment contributes to the discussion, even though I would personally love to see commenter go into more detail.
What kind of IPv6 allocation do they provide?
They also let you just upload an ISO and install any OS you like from there, which is handy for non-default FreeBSD configurations like ZFS-on-root
The price you see in the huge font is the price you'll pay at the end of the month...
https://wiki.archlinux.org/index.php/Install_from_existing_L...
Then like all cloud services, things get bad when you can't properly boot or start the network services. I used to run Arch with a more recent kernel and that kind of happened after an upgrade.
To be fair, I can understand why they don't want to support Arch as it's probably a bit of work, but they are also a cheap service, so some people (like me) like to have a little server running there just for personal stuff (IRC bouncer, ssh tunnel etc.). And in this case, you want something closer to your own system.
They still provide a good service in my opinion as I still use them :)
I'd love if someone explained it.
Same as ec2 yes, but aws provides ebs.
I mean, what kind of company links directly to blog entries, with incomplete and outdated information, all across their web-site?
Ain't nobody got time to read the blog comments and figure out what's the current status of stuff is.
Does anyone really disagree that documentation at DO is total crap?!
If it wasn't total crap, why would their employees link (on social media) to the upstream www.freebsd.org instead of any kind of FAQ on their own website? https://news.ycombinator.com/item?id=8890383 Oh, right, because DigitalOcean's documentation (about their own features (and disabling of features from FreeBSD)) is absent and non-existent!
OpenBSD -- the world's simplest and most secure Unix-like OS. Creator of the world's most used SSH implementation OpenSSH, the world's most elegant firewall PF, the world's most elegant mail server OpenSMTPD, the OpenSSL rewrite LibreSSL, and the NTP rewrite OpenNTPD. OpenBSD -- the cleanest kernel, the cleanest userland, the cleanest configuration syntax and some of the world's best documentation.
FreeBSD, on the other hand, is becoming more of a testbed for experimental, some would even say unnecessary technologies: https://news.ycombinator.com/item?id=8546756. It's also having a hard time catching up to OpenBSD: http://itwire.com/business-it-news/open-source/62641-crypto-....
> All the coolest stuff in FreeBSD comes from OpenBSD
This is juvenile "I'd rather push a Ford than drive a Dodge" level commentary. It's not true, and isn't even interesting.
That any BSD is getting support is a good thing -- it opens the door to others following, and is good news.
I disagree. Jails, ZFS, and DTrace did not come from OpenBSD.
The source you have for the 'testbed' for new technologies makes the claim but barely has warrant for it. On the other hand, OpenBSD is much more liberal about breaking compatibility especially when it involves security. While I'm not going to excuse OpenSSL, NTP, or Sendmail they are all general robust software that has been in use for decades. Aside from LibreSSL the OpenBSD rewrites have been incompatible.
FreeBSD also offers a number of incredibly compelling features outside of what OpenBSD can, or will offer in the short to medium term. I'll just list them: virtualization with Bhyve, boot from zfs, a linux compatibility layer, a much more modern package manager, official java support, the ability to install binary blobs.
None of this is to say that OpenBSD isn't a great choice, but recognize there are reasons to choose both platforms and that one doesn't need to spread FUD to advocate for their favorite platform.
I think you've incorrectly interpreted OpenBSD's intentions. OpenBSD doesn't support a MAC framework because they believe the best approach to security is correctness, rather than trying to achieve security by adding features which results in more complexity, making it more difficult to ensure correctness. A common mistake people make is thinking that OpenBSD's primary goal is security; their primary goal is correctness. This just happens to result in better security more often than not.