Ask HN: What do you run on a $5 VPS that's worth keeping online 24/7?
DHH's "AI shed" idea got me thinking about getting a small $5–10/month VPS.
I'm a Linux guy and have on many points of my life have a personal server. So I like the idea of having something always on, but I’m not sure the maintenance is worth it when most things can just run on my laptop.
That said, I tend to do things myself and only later realize I could have automated or delegated them, so I may have a blind spot here.
If you have a cheap VPS or mini PC, what actually ended up being useful long-term? Anything that saved enough time or replaced enough subscriptions to justify keeping it around?
487 comments
- qBittorrent for "Linux ISOs"
- Jellyfin so I can watch/read/listen to my "Linux ISOs"
- Tailscale so me, my family and friends can watch/read/listen to my "Linux ISOs" from anywhere in the world
- Self hosting my photo albums. Immich is a handy choice for this. Very useful for personal photos you don't want to trust to strange tech companies.
- Gitea for self-hosting git repos for some personal projects I have not open-sourced.
With qBittorrent.
> Do you prune the ISOs you've already installed somewhere, or are they kept around to be re-installed?
I keep them all. Compression algorithms are pretty good these days, as is storage density.
But yes, Jellyfin can also natively transcode formats on the fly if you stick a GPU in there: https://jellyfin.org/docs/general/post-install/transcoding/
Ask yourself what other types of media can be had on popular torrent sites.
> Linux ISO: A codeword for copyrighted material shared without permission, usually over P2P networks.
[1] http://linux-iso.urbanup.com/2782626
If you don't think 2 hours of professionally produced content is worth $10, well that's why AI isn't the only thing destroying art and culture.
So if you want to rip recent Blu-ray, you will need to buy makemkv (they do have a 1-month trial tho). But worse, if you want to rip 4k Blu-ray, you will need a specific br-drive that makemkv support (as I understand, they make custom / modified firmware for some drives, allowing to read the protected data). The issue is that there is barely anyone still making br drives and whenever makemkv support one it goes out of stock and/or become extremely expensive on the second hand market.
This is really annoying me because I know this is the end of the physical market for movie. I fully expect Blu-ray to completely die off in a few years. Movie will probably only be available through streaming services, which means it will be harder and harder to get a good quality encoding. With recent codecs (av1, h265, will see how av2 does), the quality that streaming services is okay, but we are far from what a full Blu-ray dump allows today.
That can change (and the official communication is that its only free while in beta) but my guess is that the free beta is the main thing holding back alternatives. MakeMKV does solid work but it's not rocket science and a lot of parts (like all the complementary LibreDrive / UHD firmware work) doesn't even have a paid license check at all.
> I fully expect Blu-ray to completely die off in a few years.
I don't. It might continue to shrink and thereby get more expensive but the distributor market is still very healthy and has more active competition than movie production itself. The biggest danger is disc production but I don't think its impossible to shift that over to a BD-on-USBFlash or whatever else is convenient if needed.
It's rare that the latter goes for < $10.
I used to do this, until I learned the value of offsite backups.
Learn from my mistake (if you aren't already :) ).
Inherently to inner copy it provides some redundancy.
Backups need more than one copy.
Constructing a RAID5 with 4 drives provides failover and recovery if one of the drives dies.
A real backup protects both against hardware faults and accidental deletion.
Within a storage array though it does provide redundancy at that level, and generally speaking most people don’t access a raid or NAS at a shell level only where they drop rm -fr’s
Separate and offsite backups are non negotiable, however running a raid 5 locally can greatly reduce storage rebuild/restore time, if a single drive fails the rest of the raid continues to work fine until replaced.
My photos are on: Captured devices(phones, camera). Immich on my homelab, and google photo(which is lossy, but better than nothing).
Granted, an average person most likely will never mess up, but in google-land the surface area where to make that mistake is quite large.
I didn't check ToS of proton drive, but in my experience, every cloud storage has requirement about what kind of data is allowed to store(after all, they dont want to accidentally store illegal stuff).
I then tested restore vis kopia desktop onto my desktop to validate restore works.
13 eur for 5tb is more than enough for immich backups for my personal use.
It is generous of you to share your "Linux ISOs" with your family and friends.
It really was common in the early 2000s for Linux distros to provide torrent downloads. Internet speeds were such that downloading peer‐to‐peer could be significantly faster, and (probably more importantly) it saved the distro mirrors a lot of bandwidth. I think this practice has mostly died out among newer distros, but distros from the era such as Ubuntu or Arch still provide them.
If you're privacy conscious, please be aware that Tailscale by default is creating behavioral metadata from all of those computers for the Room 641As of the world about everything you do on your supposedly “private” network: https://tailscale.com/docs/features/logging
“This includes real-time events for open and close events for every inter-machine connection (TCP or UDP) on your network.”
Headscale turns the $5 VPS into the thing that connects my laptop to my other compute resources while I am out and about.
For example, you can create a token that grants VPN access with inbound SSH as the only allowed traffic. Add that as a secret to GitHub Actions and now you can ad-hoc debug failing CI via `tailscale ssh`.
https://www.wireguard.com/quickstart/
Definitely a place for both services, IMO.
https://sanctorum.se
> no mobile clients
You can't turn off the centralised element of Tailscale though, i.e. IP tracking etc.
So for the privacy conscious Tailscale remains a poor choice. Especially as they operate under US jurisdiction:
So CLOUD, PATRIOT and friends very much apply to Tailscale.You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.
What is Tailscale getting that my ISP and google/Facebook via their pixels and tracking scripts aren't?
Like? What exactly could they plausibly do, that I should care about, if I otherwise have no reason to worry about these institutions?
In case you were not aware, spooks have focused on metadata analysis over "full take" (data) analysis for a very long time because they are far more effective and require less data to analyse. This has been the case at least since the early 2000s with Stellar Wind but arguably even the Stasi worked this way -- they cared a lot more about who you were talking to than what you were talking about. The Snowden revelations in 2013 talked almost entirely about metadata-only systems that were being used to invasively surveil the world.
If your point was more "I have nothing to hide" then you can find plenty of articles online to disabuse you of that notion. There's even a Wikipedia article about it[2].
[1]: https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-... [2]: https://en.wikipedia.org/wiki/Nothing_to_hide_argument
Can I even hide from NSA level adversaries without employing extreme methods? Assuming "no", then for this particular threat model do the tools employed next matter?
I initially used WireGuard, but as my home lab scaled, it became unwieldy. Some people could work around these limitations with bash scripts, but if you have an heterogeneous environment (esp iOS clients), making programmatic configuration changes to WireGuard becomes trickier.
Today I use Tailscale (with Headscale as the control plane) for all users, and WireGuard as a emergency access to key servers.
~10W is what my socket reports for regular use on the M2 Pro.
They are not cheap anymore, unfortunately, but at least you get much more performance out of them than you would from some $5 VPS.
People have commented a lot already, but one thing I do that I haven't seen others already doing yet is I run a news summarization pipeline with Miniflux and Flatnotes.
All my feeds are in one of two categories; Summarize and NoSummarize. Once a day, a script fires at everything unread in the Summarize category, pulls the full text from Miniflux (or calls a scraping service if it appears to only have an article stub), groups similar articles to together with a 60 to 80 word summary, and for everything not grouped together it gives each article a 20 word or so summary. Just enough for me to know if it warrants a full read or not. Then it takes that a posts the digest to a markdown file in a Flatnotes folder. Flatnotes I expose via Tailscale Funnel so I can read it anywhere, including on my work laptop if I'm at the office.
Why Miniflux and Flatnotes and not other options? Mostly because those two are about as lightweight as it gets with still pleasing interfaces and basic features.
- family ai knowledge / data store MCP https://setoku.com/
I love interserver.net which starts at $3/mo and has much better network and cpu than providers with twice the specs. I benchmarked a bunch for a hobby project. I also run some professional stuff there (worker servers for https://hedgy.works). Also LAX locations with great ping in California.
BTW I do think this is a golden age for the humble VPS. If you’re daring you can totally let Claude code be your sysadmin.
- laptop, phone (termux), Linux VPS, and home inference machine can all see each other on the same Wireguard network via the VPS.
- Todo list web app for our family shopping list. Used daily for many years now.
- Personal daily updating dashboard with important numbers I care about, life metrics, weather, etc.
- Projects priority list which tells me what to do each day based on last update for each project (each project has a desired frequency of work and it prioritises by "lateness"). Checks git activity and RSS feeds to see what I'm neglecting.
- "Note to self" app and voice automation which transcribes and adds to my Joplin notebook on my laptop.
- AI agent on my phone I can long-press power button and give spoken commands ("add milk to the shopping list"). Uses private home inference machine, see below.
- Social media POSSE syndication scripts. Mastodon posts are syndicated to other networks.
- Blog posting pipeline from my Joplin notebook out to the web.
- Home inference machine (mostly solar powered) I use for personal finance, automation, note search, and other sensitive AI tasks.
- Self-hosted calendar and contacts (separate VPS but same idea).
I don't log in to Google at all. With LLMs now it's very little work to build and maintain these things. Absolutely wild time to be a home tinkerer.
Toggling users on/off also works great, and disabled users don't count towards the limit.
(sorry if this question doesn't make sense)
Ollama serves models on an OpenAI compatible API directly on the inference machine, which most open source harness software will connect to. The inference machine has a name like inferencemachine.local on my home network so the Ollama URL looks like http://inference machine:11434/v1 to connect to any model I've downloaded.
This!! There is no end to the side projects and idea lists, and all of them feel possible
Also, what inference hardware are you using that's so efficient you can do it solar powered?
The inference machine is a basic headless gaming PC with a second hand RTX3090 and 64GB RAM.
The solar panels clock 5kW which is mostly fed back into the grid. It's sunny a lot here. The maximum consumption of the PC is 700W and it's mostly idle. Broad strokes we're net positive.
tierhive.com has super cheap VPS, as low as 10 cents/month for a tiny one (128MB ram, 1GB SSD). ipv6 only, with a NAT proxy for ipv4 I think. It's quite possible to run a useful basic Debian server on that. I ran one with 32MB ram for a while.
You’re going to get a lot of affirmative answers here, which is maybe what you’re looking for. Maybe you’re brainstorming.
But I’ll affirm what you’ve probably been thinking all along: It’s not worth it. I set up a Lenovo ThinkCentre to be my personal Linux server running on my home network. I could use it for backups, ssh, taskwarrior, etc. It did solve some problems.
It also creates problems. The biggest is that it’s another computer to maintain. It needs updates. Critically, it needs security. You need to secure the ports and services, use vpn, etc.
I found that none of the gains were worth the maintenance. For my problem set, it’s easier to keep multiple cheap laptops in multiple locations and use a flash drive (rather than network) to move data between them.
For backups, specialized cloud services (currently Arq going to B2) does the job better, along with Carbon Copy Cloner to a local volume.
For me, having to maintain and secure it was too much work. A vps may have been easier in some ways, but harder in others.
So in the end you may be right: just run things on your laptop.
Maintenance is running upgrades once a week/month -> 10mn
Depending on how critical your data is, you can rely on the provider's backup policy or setting up something as simple as a cron rsync on an external provider -> 2h to setup
It’s simply more cost effective to run your own micro data centre once you have enough workloads. I suppose if you have absolutely no office anywhere and don’t need office Internet, electric, etc. then it’s worth it.
Secondary was for bittorent'ing.
I also run a few personal web services: Immich, Gitea, Bookstack, Jellyfin, and more. That cheap VPS couldn't handle it. I run the services on a computer in my home office. Caddy runs on the VPS with one proxy line per service. Data is, of course, exchanged via Yggdrasil. The domains for the various services all map to the VPS’s IP addresses. Caddy then handles the routing correctly. The system works simply. I can even run storage-intensive services like Jellyfin, and it only costs me a few euros for the VPS.
[0] https://yggdrasil-network.github.io/
Does it mean that the VPS has to be in-between all the traffic, or do we punch holes through the NAT for direct connections?
The Yggdrasil client is installed on every computer. I'm running Debian. I have no idea how well it works on Mac or Windows. Yggdrasil assigns a key pair to each computer.
On the VPS, the config is modified in two places:
This makes the VPS listen for Yggdrasil connections. This ensures that it only accepts connections from the specified computers. You can also leave that part out. But then any Yggdrasil client out there could connect to your VPS.Note that this is only the config for the VPS.
I only make one change to the config of the other computers:
This causes them to actively connect to the VPS.> Does it mean that the VPS has to be in-between all the traffic, or do we punch holes through the NAT for direct connections?
It depends. If the computers can reach each other on a local network, the Yggdrasil clients will automatically find each other and connect. To do this, you wouldn't have had to change anything in the default configuration. you would simply have had to install and start the Yggdrasil client on the computers.
With NAT in between, they wouldn’t connect on their own. But since they’re configured to actively connect to the hub in any case, they can still see each other via the hub and exchange data even in this scenario. Yggdrasil handles routing and NAT traversal. If both paths are available (locally or via the VPS), Yggdrasil defaults to the local path. But in the general case (where all other computers are behind NAT), all traffic would go through the VPS.
Special case: If only one of the two computers is behind NAT and you want a direct connection, then the accessible computer corresponds to the VPS in the configuration above.
Immich, Jellyfin, Gonic, Snapcast, Slskd, Audiobookshelf, Transmission, Automatic Ripping Machine, Vaultwarden, Frigate, Home Assistant, Actual Budget, Pocketbase, Vikunja, Forgejo, Readeck, Backrest/Restic, Gotify, Uptime Kuma, Homepage, Caddy, Shared network folder with spouse
I also run Cockpit and Beszel but don't use them often.
Router runs Adguard, Wireguard, and OpenVPN.
The only big memory guzzlers are generally proprietary software, like the unifi network controller software which basically requires an entire room of Cray supercomputers just to view your Wifi AP status.
I specifically look for efficient projects when I have a choice. Also most of my video media is in 720p. The 8 IP cameras I run in lower resolution as well, though that's mainly to avoid network bandwidth issues.
Honestly I have not run into any memory issues.