For awhile I’ve liked the idea of using a VPS for “critical” services. Currently looking at running:

  • Authentik
  • Komodo (with periphery agents on local boxes)
  • Uptime Kuma
  • NTFY
  • Panglolin (or Cosmos Cloud?)

So, first of all, to folks already using a VPS, do you think it’s worth it? Do you think I’m missing anything? Happy to discuss/research alternatives, too. I’ve thought about TinyAyuth+PocketID in place of Authentik. While I think Authentik is probably more complex (and likely overkill), it’s a single solution. That said, I haven’t played with TinyAuth/PockedID.

Second, I was pretty interested in Pangolin until I saw Cosmos Cloud mentioned elsewhere. It seems like it actually ticks a lot of boxes:

  • Built-in authentication
  • Reverse Proxy
  • VPN (At least for local-to-VPS connection, but possibly also for external clients?)
  • Docker management(?): They have an “app store” that’s all docker images, so there’s some docker capability built-in. Not sure yet if it can handle multiple hosts like Komodo.
  • DNS (I would still keep at least 1 local pi-hole instance)

Looking at the doc for chaining proxies and hiding IP, here, it mentions creating an A record for services hosted on a different server. I’m curious to know if this means Cosmos will only manage DNS for services hosted on the same box. Honestly this seems kind of odd, unless I’m misunderstanding how proxy servers work.

Anyway, I know this was a bit of a meandering post. Curious to know thoughts on my original plan, but also if anyone has played with Cosmos, I’d like to hear your thoughts.

Lastly: This morning, I found this interesting write-up to manage container updates using Forgejo, Renovate, and Komodo. Another rabbit hole to explore!

EDITS:

  • Spelling
  • motruck@lemmy.zip
    link
    fedilink
    English
    arrow-up
    7
    ·
    1 day ago

    Wow lots of people who can’t handle hosting. Ignore the nay sayers. Run your VPS just you know keep it up to date, back it up and use a long stable release.

    It seems like the same crowd that can’t figure out email also can’t figure out running a server in general on the internet. Go figure.

    • irmadlad@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      I sure haven’t seen any nay sayers. Just some people giving advice, and sharing their experiences.

    • kossa@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      16 hours ago

      I get the same feeling, like, as if three letter agencies from all over the world start targeting your server specifically in 300 ms.

      What happens is, yes, your server is immediately bombarded by ScriptKiddies from all over the world, and if you set up root SSH with hunter2 as password, that thing is taken over immediately. But if you only allow keyfile SSH you’re 98% there already ¯\_(ツ)_/¯