Ask HN: What do you run on a $5 VPS that's worth keeping online 24/7?

301 points by mariocesar · 487 comments
DHH's "AI shed" idea got me thinking about getting a small $5–10/month VPS.

I'm a Linux guy and have on many points of my life have a personal server. So I like the idea of having something always on, but I’m not sure the maintenance is worth it when most things can just run on my laptop.

That said, I tend to do things myself and only later realize I could have automated or delegated them, so I may have a blind spot here.

If you have a cheap VPS or mini PC, what actually ended up being useful long-term? Anything that saved enough time or replaced enough subscriptions to justify keeping it around?

487 comments

On my home server (just an older desktop PC)

- qBittorrent for "Linux ISOs"

- Jellyfin so I can watch/read/listen to my "Linux ISOs"

- Tailscale so me, my family and friends can watch/read/listen to my "Linux ISOs" from anywhere in the world

- Self hosting my photo albums. Immich is a handy choice for this. Very useful for personal photos you don't want to trust to strange tech companies.

- Gitea for self-hosting git repos for some personal projects I have not open-sourced.

7bit
How many Linux ISOs are stored on your $5 VPS? One?
ehe78qhe OC
Like I said, this is on an old desktop PC that I shoved some spare SSDs into. I have a few thousand Linux ISOs on there. I have an rclone job running regular encrypted offsite backups as well, so that my Linux ISOs are safe from hardware issues.
How are you adding new Linux ISOs? Do you prune the ISOs you've already installed somewhere, or are they kept around to be re-installed?
> How are you adding new Linux ISOs?

With qBittorrent.

> Do you prune the ISOs you've already installed somewhere, or are they kept around to be re-installed?

I keep them all. Compression algorithms are pretty good these days, as is storage density.

I'm surprised you save much space since ISOs are usually stored in already compressed formats
No he means a full length Linux ISO can be as small as 700 MB, I personally prefer 1.4 GB
I prefer my Linux ISOs to one or two orders of magnitude more fully featured than that.
Weirdly, my "Linux ISOs" are compressed in x265 :)
Which is only marginally more effecient than the H.264 encoding that many of them are delivered in. And the biggest shiniest Linux ISOs already use H.265 out of the box.
Does this mean you have to decompress your "ISOs" when you want to watch them ? Does jellyfin support this ?
They're compressed in x265, most web browsers can decompress that natively ;) Heck, when you watch something on YouTube you are decompressing the content ont he fly

But yes, Jellyfin can also natively transcode formats on the fly if you stick a GPU in there: https://jellyfin.org/docs/general/post-install/transcoding/

Oh i thought you went 1 step further, compress all those "ISO" into 1 single blob.
Since Linux ISOs demand random access for a good user experience most of the relevant compression formats support that and so compressing as a blob wouldnt't really get you much but also not prevent individual access.
jotato
I picked up a new hobby of buying Linux ISOs from thrift stores. I usually get them for $1/each. Up to 300 now - all mine. Jellyfin is great to organize them
ehe78qhe OC
I have some Linux ISOs I ripped myself, but it can be especially hard to find older ISOs from other countries - you usually can't find them on normal websites. It's really nice to have them on my own server and not worry about them disappearing someday.
I’ve been collecting a lot of post-war Italian neorealism Linux ISOs and running a DHT indexer has made it pretty easy to find distros that may be out of print.
It’s so hard to find drivers for those
First I've heard of this DHT indexer concept. Is this bitmagnet? What kind of resources does it require? Thanks for any info you can provide.
I used to have a substantial collection of very rare Euro/US short and performance art films on DVD that were lost to the sands of time during a period of my life where my work led me to be mostly nomadic. In retrospect, I wish I would have ripped the collection onto a hard drive as most of them are completely irreplaceable now on DVD.
ozozozd
Thrift stores? Really?
psst, they're talking about movies
is this an internet secret code I am missing ?
Many Linux ISOs are distributed via torrents.

Ask yourself what other types of media can be had on popular torrent sites.

wyre
The two things that torrents are best at are downloading Linux ISOs and pirating content. So using qbittorrent to download Linux ISOs is usually code for piracy, since torrenting Linux ISOs is legal and piracy is not :)
Piracy is legal if you're big enough
selcuka
It's even in the Urban Dictionary [1]:

> Linux ISO: A codeword for copyrighted material shared without permission, usually over P2P networks.

[1] http://linux-iso.urbanup.com/2782626

Yes there’s usually a good cache for very cheap though most are scratched up
Problem is the resolution. I don't want to experience paid 480p in a world of free 4k.
Blu rays aren't bad either. The glory days were back when Netflix was cheap and there was an oversupply (in that era I built up a library of hundreds), but even today you can get most things in 1080p for $10 or less.

If you don't think 2 hours of professionally produced content is worth $10, well that's why AI isn't the only thing destroying art and culture.

I'm back in to collecting physical media as well. I get my wife to use her Facebook account to find stuff on marketplace. Lightly used bundles can get movies down to like a dollar per.
maeln
The issue with Blu-rays is they are costly to rip. Basically, the only software that let you do it right now is MakeMKV, and it's proprietary. I believe that the VLC team is working on some open-source solutions, but last time I checked, it was only able to read old Blu-ray (which is understandable, they have to care about potential copyright and drm issue, unlike the people behind makemkv).

So if you want to rip recent Blu-ray, you will need to buy makemkv (they do have a 1-month trial tho). But worse, if you want to rip 4k Blu-ray, you will need a specific br-drive that makemkv support (as I understand, they make custom / modified firmware for some drives, allowing to read the protected data). The issue is that there is barely anyone still making br drives and whenever makemkv support one it goes out of stock and/or become extremely expensive on the second hand market.

This is really annoying me because I know this is the end of the physical market for movie. I fully expect Blu-ray to completely die off in a few years. Movie will probably only be available through streaming services, which means it will be harder and harder to get a good quality encoding. With recent codecs (av1, h265, will see how av2 does), the quality that streaming services is okay, but we are far from what a full Blu-ray dump allows today.

MakeMKV has an effectively perpetual free trial right now. It's not like old shareware were you have to pay after a month but rahter that you have to feed it a new free activation key every month and maybe wait a couple of days for one to be posted.

That can change (and the official communication is that its only free while in beta) but my guess is that the free beta is the main thing holding back alternatives. MakeMKV does solid work but it's not rocket science and a lot of parts (like all the complementary LibreDrive / UHD firmware work) doesn't even have a paid license check at all.

> I fully expect Blu-ray to completely die off in a few years.

I don't. It might continue to shrink and thereby get more expensive but the distributor market is still very healthy and has more active competition than movie production itself. The biggest danger is disc production but I don't think its impossible to shift that over to a BD-on-USBFlash or whatever else is convenient if needed.

fooqux
I hate blueray. At least for having physical copies. Too many times I've tried watching something I own only to have it fail due to my player not having current decryption keys. Perhaps it's more of a player issue and less of a disc issue, but it's still a problem with the overall format.
MakeMKV hasn't failed me yet. As always, only people fully abiding by corporate rules suffer.
rwmj
The one time I actually bought a Bluray, I couldn't play it because of fricking Region Coding. Like this is the 2020s and you still have to deal with that BS?!
1080p doesn't really say much when that could be an old DVD-era master with questionable color correction crammed onto a BD25 disc with other features/extras vs a modern archival-quality master professionally encoded to 40+ GB.

It's rare that the latter goes for < $10.

xrd
What kind of thrift store sells these? In what country?
achenet
I suspect "Linux ISOs" are not actual Linux .iso images but ~pirated~ movies, music, and digital books ;)
tomekw
No way!
Joking aside, a few early commercial Linux distro (Red Hat, Yellow Dog, SuSe, Corel Linux) had really nice packaging and media artworks. I'd love to collect them.
mrngld
Yes, seriously, my intro to linux as a kid was seeing the slick Red Hat boxed media on the shelves at CompUSA.
emeril
ding ding ding
bambax
In France many public libraries let you rent them for free (or a ridiculously low annual subscription); you take them home, copy them, return them, and it costs nothing.
maeln
And it is legal to do so ! We pay the "copie privé" tax for that reason.
mkesper
Hmm, public DVDs I know often have read errors.
hoherd
Same with USA. I was surprised at the variety of platforms supported.
ISOs of what, music or video?
$1 won't get you Linux ISOs up to modern display standards. Great if that works for you but the high end is more like $20+ (emphasis on the +, taxes and shipping not included) per Linux ISO so its understanding why many might prefer sharing them digitally. And that's before getting into cases where the Linux ISO vendors don't even want to give you the specific version you want.
mrngld
Did you see the 'thrift store' part of his comment? I do the same thing as him, and depending on the location around town, an ISO on a DVD can be as little as 50 cents, and a modern Linux ISO on bluray, including 4K (though rare I see those) are rarely over maybe $3.
I mean just say you’re pirating…
ehe78qhe OC
Whaaaaaat? That's illegal! I'm just an OS enthusiast!
We all enjoy a bit of sailing on the OS (Open Sea)
Especially using Sailfish OS
Boomers like to prove they can still have fun
leptons
As a gen-x'er, it's my birthright
jedberg
> Self hosting my photo albums

I used to do this, until I learned the value of offsite backups.

Learn from my mistake (if you aren't already :) ).

What happened?? As someone who is currently doing this without backups…
HDD failure probably
tlavoie
Or a house fire, or flood...
jedberg
I moved homes and damaged both drives because they traveled together.
I have mine in a RAID 5 setup rn because I was scared about that, but I definitely should set up offsite backups, it’s just so expensive
pava0
Raid is not a backup :( For the really important data (photos, documents, ecc) a small 1GB raspberry pi + USB external HDD works great as a Borg server for daily backup, there is no need for a full NAS when you can store all important data in less the a handful of terabytes
j45
A raid is one layer and one copy in a backup.

Inherently to inner copy it provides some redundancy.

Backups need more than one copy.

RAID is not a backup because anything happening within that file system happens to both drives immediately.
ZFS snapshots can help, but this is one layer of a comprehensive backup strategy.
j45
both drives? Only 2 mirrored drives isn't really what a RAID can be.

Constructing a RAID5 with 4 drives provides failover and recovery if one of the drives dies.

You can have as much redundancy as you like on your RAID, but if you fat finger an rm -r it's all gone.

A real backup protects both against hardware faults and accidental deletion.

j45
I’m not implying Raid 5 on its own is a complete backup.

Within a storage array though it does provide redundancy at that level, and generally speaking most people don’t access a raid or NAS at a shell level only where they drop rm -fr’s

Separate and offsite backups are non negotiable, however running a raid 5 locally can greatly reduce storage rebuild/restore time, if a single drive fails the rest of the raid continues to work fine until replaced.

I use RAID1 so that each disk can be pulled and used as standalone.
ehe78qhe OC
I have an encrypted offsite backup. A lot of people I know with home servers work out a deal with a family member to have cross-backups with each other.
jedberg
Sadly I don’t have a family member that I can trust with that, but I do put an encrypted copy on AWS glacier and I have an encrypted volume in Dropbox.
Yeah I do something similar, a local backup on an external drive that mostly lives in a different place and a last resort backup in glacier
What ist your plan if you die? Do you have a spouse that will be able to read your-and-your-spouses data?
Yeah. Which is why I use Ente.com. But I should have a offsite backup of ente.com copy self-hosted as well maybe.
That's why you always practice 3-2-1 with important data.

My photos are on: Captured devices(phones, camera). Immich on my homelab, and google photo(which is lossy, but better than nothing).

tomrod
Proton Drive may work better here?
I am honestly not sure. I use GG photo because that what i use first and i was too lazy to investigate better deal. Also, i know Google does really well at keeping my data available, which is what you want for backup.
tommica
One mistake with your google account and poof, everything is gone.

Granted, an average person most likely will never mess up, but in google-land the surface area where to make that mistake is quite large.

Luckily i have 321 back up, don't i ?

I didn't check ToS of proton drive, but in my experience, every cloud storage has requirement about what kind of data is allowed to store(after all, they dont want to accidentally store illegal stuff).

I just purchased a hetzner storage box and used claude to configure kopia to backup to it.

I then tested restore vis kopia desktop onto my desktop to validate restore works.

13 eur for 5tb is more than enough for immich backups for my personal use.

I use backblaze with restic. Got about 300GB up there, fully encrypted, keys in 1Password.
ostros
That’s sad :( Where do You backup offsite now?
How are you sharing tailscale with your family and friends? do you run the server yourself?
xgulfie
Tailscale is free for home use and lets you invite people to your network by email
jawns
In my neck of the woods "Linux ISOs" is a euphemism for porn.

It is generous of you to share your "Linux ISOs" with your family and friends.

PetahNZ
"Linux ISOs" is just anything pirated in general.
I’ve usually heard it as a euphemism for torrents specifically, since these would be one of the main legal uses of torrents.
All my Linux ISOs are actually FreeBSD.
Mine are temple OS
bambax
First time I heard this. When did it start? It's pretty funny.
bentley
Very common on Slashdot fifteen or twenty years ago. The Pirate Bay trial was a big story back then, for instance, and there was advocacy from the copyright cartels to ban the bittorrent protocol. Another hot story was when Comcast dropped customers for using too much data despite being on “unlimited” plans, justified because only a pirate would download so much. Hence, “You can’t do that, I use bittorrent to download my Linux ISOs!”

It really was common in the early 2000s for Linux distros to provide torrent downloads. Internet speeds were such that downloading peer‐to‐peer could be significantly faster, and (probably more importantly) it saved the distro mirrors a lot of bandwidth. I think this practice has mostly died out among newer distros, but distros from the era such as Ubuntu or Arch still provide them.

bambax
Thanks!
So not a $5 VPS
ehe78qhe OC
read the OP, they mentioned home servers too
Lammy
> - Tailscale so me, my family and friends

If you're privacy conscious, please be aware that Tailscale by default is creating behavioral metadata from all of those computers for the Room 641As of the world about everything you do on your supposedly “private” network: https://tailscale.com/docs/features/logging

“This includes real-time events for open and close events for every inter-machine connection (TCP or UDP) on your network.”

serf
good alternatives that do near the same thing?
jjordan
self-hosted open source alternative Headscale/Headplane. Uses the Tailscale client without their SaaS being involved.
cls59
Same! Although, for Headplane you may need at least 1GB of RAM.

Headscale turns the $5 VPS into the thing that connects my laptop to my other compute resources while I am out and about.

What's the advantage of Tailscale anyway? I guess ease of use compared to say setting up IPSEC? I haven't played with it yet but from what I read it's just wireguard with a bit of proprietary "one click and sell your soul" magic around it?
cls59
Tailscale automates wireguard key distribution and then layers routing, DNS, network ACLs, and other niceties on top.

For example, you can create a token that grants VPN access with inbound SSH as the only allowed traffic. Add that as a secret to GitHub Actions and now you can ad-hoc debug failing CI via `tailscale ssh`.

It's a VPN essentially but just works easily and affordably. We don't stress on managing keys, secrets etc and it's SSO friendly.
stavros
How do you know their client won't send them the metadata anyway?
It is open source
chr15m
You can ask an LLM to set up a wireguard network for you with an idempotent bash script to deploy everything. You'll need a $5 VPS to bounce everything through. Works an absolute treat.
tommica
Is that the prompt you would use, or is there more to it?
The wireguard docs are pretty good, and it's probably worth it at least a little to actually understand what it does.

https://www.wireguard.com/quickstart/

chr15m
Yep and the LLM can help explain, but it is actually super straightforward. Public key cryptography and the text file configs are tiny.
mkesper
Actually I wish they would be a lot more verbose and explain the details a little bit better.
chr15m
You could try with that as a prompt. I have a repo set up with all of my sysadmin scripts and so the LLM had that as additional context.
Netbird has a self hosted option
Netbird!
mrngld
I saw all the Netbird recs here so looked into it briefly. Depends I guess on what you use Tailscale for. Tailscale Funnel is easy and stable. Self-hosted on Netbird is ... a bit more involved.

Definitely a place for both services, IMO.

jvink
Sanctum! Entirely free and open-source and PQ-secure.

https://sanctorum.se

klntsky
tl;dr

> no mobile clients

Netbird, been using it for about 6 months now with no complaints. Fully OSS, mobile clients, etc.
efficax
o no, they’re seeing open and close events between my laptop and my vps and database. the fbi will surely bring the hammer down on me
ehe78qhe OC
i literally do not care about that metadata
Lammy
Sad
Why? It's TCP/UDP connection data for troubleshooting you can turn off. No privacy issue there.
> connection data for troubleshooting you can turn off. No privacy issue there.

You can't turn off the centralised element of Tailscale though, i.e. IP tracking etc.

So for the privacy conscious Tailscale remains a poor choice. Especially as they operate under US jurisdiction:

     - "Tailscale US Inc., a Delaware corporation with registered address at 447 Sutter St Ste 405 #543, San Francisco, CA 94108, USA"
     - "For any dispute not subject to arbitration you and Tailscale agree to submit to the personal and exclusive jurisdiction of and venue in the federal and state courts located in New York, NY".

So CLOUD, PATRIOT and friends very much apply to Tailscale.

You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.

I ran Headscale for a while, and now wireguard directly, but never really considered it to be more private.

What is Tailscale getting that my ISP and google/Facebook via their pixels and tracking scripts aren't?

> You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.

Like? What exactly could they plausibly do, that I should care about, if I otherwise have no reason to worry about these institutions?

cyphar
"We kill people based on metadata." - NSA Chief Gen. Michael Hayden, 2014[1]

In case you were not aware, spooks have focused on metadata analysis over "full take" (data) analysis for a very long time because they are far more effective and require less data to analyse. This has been the case at least since the early 2000s with Stellar Wind but arguably even the Stasi worked this way -- they cared a lot more about who you were talking to than what you were talking about. The Snowden revelations in 2013 talked almost entirely about metadata-only systems that were being used to invasively surveil the world.

If your point was more "I have nothing to hide" then you can find plenty of articles online to disabuse you of that notion. There's even a Wikipedia article about it[2].

[1]: https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-... [2]: https://en.wikipedia.org/wiki/Nothing_to_hide_argument

close04
Can you be on the internet and avoid the collection of metadata that can eventually be accessible for the NSA or other TLA? You have an ISP which logs everything, same for your destination endpoint, and those logs are already being correlated.

Can I even hide from NSA level adversaries without employing extreme methods? Assuming "no", then for this particular threat model do the tools employed next matter?

Why don’t people just use Wireguard?
Once you get to N = >10 devices, and expect some degree of decentralized communication between them you find yourself maintaining N^2 entries. Every change to the set of public keys, require you updating N entries. Things get worse once you want consistent rules on what-device-should-access-what.

I initially used WireGuard, but as my home lab scaled, it became unwieldy. Some people could work around these limitations with bash scripts, but if you have an heterogeneous environment (esp iOS clients), making programmatic configuration changes to WireGuard becomes trickier.

Today I use Tailscale (with Headscale as the control plane) for all users, and WireGuard as a emergency access to key servers.

tomrod
You lost me with the quotes. Why are Linux ISOs needing such broad distribution that mirrors won't handle? Those mirrors might be on full self driving cars taking people to the movies or a concert, right?
intriguing list
I have a seedbox for Linux ISOs and then sync to my home NAS with Syncthing. That way I can use private trackers and get a healthy ratio.
iso1631
If your server is 100W that's 72kWh a month. If your electricity average is more than 7 cents an hour then it's cheaper to run a $5 server.
While it's probably the case for a desktop PC, a new mac-mini has an idle power draw of < 5W.

~10W is what my socket reports for regular use on the M2 Pro.

They are not cheap anymore, unfortunately, but at least you get much more performance out of them than you would from some $5 VPS.

Good luck finding a $5 server with enough storage for a decent Linux ISO collection.
emeril
usbx gives you 1tb for that which is enough unlike you're an archivist
scrivna
i think usbx means https://ultra.cc/
u8080
N100/N95 idling at <5W and ~20W on full load while also quite performant
GitHub also has free private repositories, but I guess your server has a much better uptime than them.
emeril
why not use just usbx for your "iso" needs - it costs $5-$15/month and might be cheaper than your home kwh usage and is less headache
What does a Linux ISO sound like?
n2j3
qBittorent (vueTorrent frontend) , jellyfin, tailscale, readeck, cloudflare tunnels (should replace with something else), beszel
mrngld
I use a Raspberry Pi, not a VPS -- as others state, Codex/Claude Code alongside things like Cloudflare and Tailscale make self hosting far easier.

People have commented a lot already, but one thing I do that I haven't seen others already doing yet is I run a news summarization pipeline with Miniflux and Flatnotes.

All my feeds are in one of two categories; Summarize and NoSummarize. Once a day, a script fires at everything unread in the Summarize category, pulls the full text from Miniflux (or calls a scraping service if it appears to only have an article stub), groups similar articles to together with a 60 to 80 word summary, and for everything not grouped together it gives each article a 20 word or so summary. Just enough for me to know if it warrants a full read or not. Then it takes that a posts the digest to a markdown file in a Flatnotes folder. Flatnotes I expose via Tailscale Funnel so I can read it anywhere, including on my work laptop if I'm at the office.

Why Miniflux and Flatnotes and not other options? Mostly because those two are about as lightweight as it gets with still pleasing interfaces and basic features.

rgbrgb
- personal websites

- family ai knowledge / data store MCP https://setoku.com/

I love interserver.net which starts at $3/mo and has much better network and cpu than providers with twice the specs. I benchmarked a bunch for a hobby project. I also run some professional stuff there (worker servers for https://hedgy.works). Also LAX locations with great ping in California.

BTW I do think this is a golden age for the humble VPS. If you’re daring you can totally let Claude code be your sysadmin.

chr15m
I have so much personal automation and small web apps running on my VPS, laptop, and on my phone it's hard to know where to start.

- laptop, phone (termux), Linux VPS, and home inference machine can all see each other on the same Wireguard network via the VPS.

- Todo list web app for our family shopping list. Used daily for many years now.

- Personal daily updating dashboard with important numbers I care about, life metrics, weather, etc.

- Projects priority list which tells me what to do each day based on last update for each project (each project has a desired frequency of work and it prioritises by "lateness"). Checks git activity and RSS feeds to see what I'm neglecting.

- "Note to self" app and voice automation which transcribes and adds to my Joplin notebook on my laptop.

- AI agent on my phone I can long-press power button and give spoken commands ("add milk to the shopping list"). Uses private home inference machine, see below.

- Social media POSSE syndication scripts. Mastodon posts are syndicated to other networks.

- Blog posting pipeline from my Joplin notebook out to the web.

- Home inference machine (mostly solar powered) I use for personal finance, automation, note search, and other sensitive AI tasks.

- Self-hosted calendar and contacts (separate VPS but same idea).

I don't log in to Google at all. With LLMs now it's very little work to build and maintain these things. Absolutely wild time to be a home tinkerer.

Anyone have ACLs or tips on them for securing their tailscale? I'm concerned at the ability for lateral without wanting to sacrifice convenience.
ACLs are super simple and work well, just dig into them. I use groups as rbac (one group per role), and share parts of my network with friends/family (game servers), and colleagues (work collab stuff, such as live coding).

Toggling users on/off also works great, and disabled users don't count towards the limit.

fooqux
I use tags. For example, anything with a server tag can accept ingress ssh connections but not egress.
What stack do you use for that home inference? I’m rolling my own with gemma4, but even with Claude helping with the implementation it’s a lot of moving pieces to figure out.
chr15m OC
Ollama running Meta's Glimmer model at the moment. I find it really capable for what I'm doing and it doesn't suffer censorship problems.
myzek
Are you using the API or is it self hosted as well?

(sorry if this question doesn't make sense)

chr15m
It is self hosted.

Ollama serves models on an OpenAI compatible API directly on the inference machine, which most open source harness software will connect to. The inference machine has a name like inferencemachine.local on my home network so the Ollama URL looks like http://inference machine:11434/v1 to connect to any model I've downloaded.

Roelven
> "Absolutely wild time to be a home tinkerer."

This!! There is no end to the side projects and idea lists, and all of them feel possible

chr15m OC
We're like the proverbial kids in the candy store!
fooqux
What do you use for you self-hosted calendar and contracts? I'm mostly de-googled but contacts especially have been problematic.

Also, what inference hardware are you using that's so efficient you can do it solar powered?

chr15m OC
Nextcloud for calendar and contacts. Android sync with DAVx.

The inference machine is a basic headless gaming PC with a second hand RTX3090 and 64GB RAM.

The solar panels clock 5kW which is mostly fed back into the grid. It's sunny a lot here. The maximum consumption of the PC is 700W and it's mostly idle. Broad strokes we're net positive.

By my standards (lowendspirit.com) $5/month is kind of high end for a VPS. I have a small personal web site on a $4 per year VPS. Other than that I have another VPS (I think around $7/m with 500GB of HDD) that I use as a personal storage server and git repo since its internet connection is much faster than my home one, etc. For a while I ran some monitoring tasks on VPSes, though I don't have any active right now.

tierhive.com has super cheap VPS, as low as 10 cents/month for a tiny one (128MB ram, 1GB SSD). ipv6 only, with a NAT proxy for ipv4 I think. It's quite possible to run a useful basic Debian server on that. I ran one with 32MB ram for a while.

Where do you get it ($4/Year VPS, presumably with IPv4 as it is used for a website) from?
It was a promo from Virmach.com. They offer stuff like that around black friday. I've had it for years. You can run a website on v6 NAT though. v6 providers like Tierhive use HAProxy to forward your traffic from v4 port 80 to your v6. You can also just set up an AAAA record and run a pure v6 website. That would probably work fine for my super low traffic thing.
Does that support HTTP/3 with TLS over QUIC (instead of TCP)
I don't know. Maybe I'll look into it sometime. I think I'd just use v6, or NAT with http/2. If you really need v4 you can still do it pretty cheap. Look on lowendspirit.com.
Nuts i thought Hetzner had the cheapest options.
oefrha
Go to LowEndTalk and Hezner will feel like the priciest option. You’ll need a good tolerance for shadiness though.
Loocid
Having never been on LowEndTalk, what do you mean by shadiness?
oefrha
It’s a forum for low end providers. You’re dealing with largely unheard of providers often with seemingly impossibly low prices, so you have to wonder if quoted specs are real (yeah before anyone tells me, the “reputable” flat rate providers are also oversubscribed), whether they’ll disappear on moment’s notice or without notice, whether you can trust your data with them, etc.
lowendtalk is shady in its own right (long story). lowendspirit is sort of a fork of it and is much better. hostballs.com is another one of those, still around but much slower.
Due to RAMpocalypse prices have greatly increased
stavros
They have the cheapest trustworthy options.
Upcloud has the cheapest I found, you can get a full VPS for less than $4.
“ Anything that saved enough time or replaced enough subscriptions to justify keeping it around?”

You’re going to get a lot of affirmative answers here, which is maybe what you’re looking for. Maybe you’re brainstorming.

But I’ll affirm what you’ve probably been thinking all along: It’s not worth it. I set up a Lenovo ThinkCentre to be my personal Linux server running on my home network. I could use it for backups, ssh, taskwarrior, etc. It did solve some problems.

It also creates problems. The biggest is that it’s another computer to maintain. It needs updates. Critically, it needs security. You need to secure the ports and services, use vpn, etc.

I found that none of the gains were worth the maintenance. For my problem set, it’s easier to keep multiple cheap laptops in multiple locations and use a flash drive (rather than network) to move data between them.

For backups, specialized cloud services (currently Arq going to B2) does the job better, along with Carbon Copy Cloner to a local volume.

For me, having to maintain and secure it was too much work. A vps may have been easier in some ways, but harder in others.

So in the end you may be right: just run things on your laptop.

wiether

  > For me, having to maintain and secure it was too much work. A vps may have been easier in some ways, but harder in others.
For security you simply setup Tailscale and only allow private network to access your VPS -> 1h max to setup

Maintenance is running upgrades once a week/month -> 10mn

Depending on how critical your data is, you can rely on the provider's backup policy or setting up something as simple as a cron rsync on an external provider -> 2h to setup

I might have said the same thing in 2023, but any coding CLI installed on Linux can rip through this work and keep it updated.
At this point, nothing. I just moved a workload off a $25 a month VPS because after 6 years of uptime, it went down, the console wouldn’t let us sign in, and their support took hours to contact and get fixed.

It’s simply more cost effective to run your own micro data centre once you have enough workloads. I suppose if you have absolutely no office anywhere and don’t need office Internet, electric, etc. then it’s worth it.

throw7
The main thing for me was having a syncthing node available 24/7. Initially I was hesitant to put one on a 3rd party vps, but there is now an untrusted device mode in beta that I haven't had any problems with so far.

Secondary was for bittorent'ing.

I use Yggdrasil [0] to connect my computers. This ensures they are always connected within a flat, private IPv6 namespace. However, two computers cannot find each other if they are both behind NAT on different networks. At least one of them must be reachable by the other via TCP. That’s why I use the cheapest VPS I could find as a globally accessible Yggdrasil hub. I’ve been running it this way for many years now, and it works flawlessly. I can even assign names for the IPv6 addresses using regular DNS, which makes things very convenient.

I also run a few personal web services: Immich, Gitea, Bookstack, Jellyfin, and more. That cheap VPS couldn't handle it. I run the services on a computer in my home office. Caddy runs on the VPS with one proxy line per service. Data is, of course, exchanged via Yggdrasil. The domains for the various services all map to the VPS’s IP addresses. Caddy then handles the routing correctly. The system works simply. I can even run storage-intensive services like Jellyfin, and it only costs me a few euros for the VPS.

[0] https://yggdrasil-network.github.io/

tommica
Can you tell how you configured the tool to accomplish this? It sounds very convenient!

Does it mean that the VPS has to be in-between all the traffic, or do we punch holes through the NAT for direct connections?

> Can you tell how you configured the tool to accomplish this?

The Yggdrasil client is installed on every computer. I'm running Debian. I have no idea how well it works on Mac or Windows. Yggdrasil assigns a key pair to each computer.

On the VPS, the config is modified in two places:

    Listen: [
      tcp://[::]:51350
    ]
This makes the VPS listen for Yggdrasil connections.

    AllowedPublicKeys: [ 
      pubkey1
      pubkey2
      pubkey3
      ...
    ]
This ensures that it only accepts connections from the specified computers. You can also leave that part out. But then any Yggdrasil client out there could connect to your VPS.

Note that this is only the config for the VPS.

I only make one change to the config of the other computers:

    Peers: [
      tcp://hub.mydomain.tld:51350
    ]
This causes them to actively connect to the VPS.

> Does it mean that the VPS has to be in-between all the traffic, or do we punch holes through the NAT for direct connections?

It depends. If the computers can reach each other on a local network, the Yggdrasil clients will automatically find each other and connect. To do this, you wouldn't have had to change anything in the default configuration. you would simply have had to install and start the Yggdrasil client on the computers.

With NAT in between, they wouldn’t connect on their own. But since they’re configured to actively connect to the hub in any case, they can still see each other via the hub and exchange data even in this scenario. Yggdrasil handles routing and NAT traversal. If both paths are available (locally or via the VPS), Yggdrasil defaults to the local path. But in the general case (where all other computers are behind NAT), all traffic would go through the VPS.

Special case: If only one of the two computers is behind NAT and you want a direct connection, then the accessible computer corresponds to the VPS in the configuration above.

This is the first time I am hearing of yggdrasil. I currently have a similar setup using Tailscale. I always thought Wireguard was teh primitive here and Tailscale just made it more convenient in the pointy clicky way. Why Yggdrasil instead of Wireguard which at the outset sounds more standard solution for this need?
tommica
Neat, thanks for sharing! Seems very convenient!
Beelink mini PC, I think S12 with N100 and 16 GB RAM, purchased before the rampocalypse...

Immich, Jellyfin, Gonic, Snapcast, Slskd, Audiobookshelf, Transmission, Automatic Ripping Machine, Vaultwarden, Frigate, Home Assistant, Actual Budget, Pocketbase, Vikunja, Forgejo, Readeck, Backrest/Restic, Gotify, Uptime Kuma, Homepage, Caddy, Shared network folder with spouse

I also run Cockpit and Beszel but don't use them often.

Router runs Adguard, Wireguard, and OpenVPN.

What's your strategy for juggling all of these on only 16GB? Docker?
That all probably fits comfortably in like 12-14GB easily
koyote
I have a similar amount running on a 16GB NUC in proxmox LXCs and it usually sits at less than half memory usage.

The only big memory guzzlers are generally proprietary software, like the unifi network controller software which basically requires an entire room of Cray supercomputers just to view your Wifi AP status.

viceconsole OC
Probably half run natively, and half on podman as systemd quadlets.

I specifically look for efficient projects when I have a choice. Also most of my video media is in 720p. The 8 IP cameras I run in lower resolution as well, though that's mainly to avoid network bandwidth issues.

Honestly I have not run into any memory issues.

Why do you need both wireguard and ovpn ?
Might as well add Tailscale if there's already those two. And IPSec.
viceconsole OC
Wireguard is easier to set up and add clients so I did that first, but it does not work over my phone's mobile data connection due to carrier filtering, whereas OpenVPN does. Also doesn't hurt to have two options.
Different platforms Tinker, tailor, ...?