urbanists.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
We're a server for people who like bikes, transit, and walkable cities. Let's get to know each other!

Server stats:

552
active users

Mark Stosberg

I'll be closing my account this month, just shy of 10 years after I opened it.

While I can still recommend them for someone who "justs wants a server" without all the complexity of Amazon, they no longer feel like the best fit for me.

My next adventure in will be physically hosting a server at my house. 🧵

With my own server at home, I'll be getting more CPU, more disk storage, more memory for a lower monthly cost, powered by solar panels.

I'll still be saving money even when factoring in paying for a static IP address, backing up the cloud and possibly adding a CDN as well. 🧵

I accept that my server may be down when the power is out or maintenance sometimes. The small web doesn't need to up 24/7.

If this solution lasts 10 years like Linode did, I'll consider that a win.

I'm considering Bunny's "Perma-Cache" CDN service has a way to keep my sites generally online even when my server is down. support.bunny.net/hc/en-us/art

To explore for another day. 🧵

🧵It's been admittedly time-consuming to set this this server up-- an old Mac Mini-- with btrfs, Ansible, restic, podman, quadlet, BackBlaze-- lots of new stuff to learn.

But my hope is to shift gears soon and focus on content instead of infra, though I'm also considering writing up various details of the setup to help other folks with similar interest spend less time figuring things out and getting stuck and unstuck.

@markstos What's your plan to keep from getting hacked?

@benfulton

1. Don't run WordPress. doesn't have a plugin system like that-- just as REST API. Security issues with it are rare.
2. No exposed server in a DMZ, only forwarding port 80 and 443 to web server. (So no exposed SSH either).
3. This reminds me: I plan to enable nightly automatic security updates with automatic reboots as needed.
4. All exposed web servers run in a container as non-root users.Unless there are chained exploits, hacks should be contained there.