https://github.com/search?q=%22cloudinabottle.toml%22&type=i...
Cloud in a Bottle: making self-hosting accessible to everyone (cloudinabottle.org)
KomoD 8 hours ago
edoceo 8 hours ago
satvikpendem 7 hours ago
edoceo 7 hours ago
doc_ick 4 hours ago
asdf88990 8 hours ago
ball_of_lint 8 hours ago
KomoD 7 hours ago
zplizzi 8 hours ago
KomoD 7 hours ago
The biggest contributor to the project in the last 3mo is andrewlaack... and we can also just take a guess that "adl" in adl-collab is AnDrewLaak.
zplizzi 6 hours ago
krelian 6 hours ago
jdiff 4 hours ago
dustin an hour ago
ChrisKnott 2 hours ago
classified an hour ago
jongjong 5 hours ago
hypfer 5 hours ago
The world would be quite miserable if "perfectly legal" would be what everyone optimizes for.
chii 5 hours ago
what you will find is that this is what corporations optimizes for. Therefore, you as a person, cannot compete with the corp.
That's why you need to become like a corp, or make the rules "socially acceptable" the same as "legal" (which is the best option).
ruszki 4 hours ago
And you can still live quite comfortably.
jongjong 3 hours ago
They're probably jealous that they never had the guts to do it themselves and prefer to rely on friends in high places or daddy big media to promote their shit for them.
Standing behind your work is good and wholesome. Fear of self-promotion is weakness.
I often talk myself up and promote my work. Especially face-to-face. If your work actually measures up to the talk then you have nothing to apologize for. You're actually educating people and doing them a service.
Don't let yourself be bunched up with snake oil salesmen who didn't actually do the work. If you did the work and nobody noticed, then it is your duty to talk it up.
The fact that a maker can't also be a seller is dumb. You can switch modes. You have to do whatever it takes to fulfill your mission.
rexpop an hour ago
What is "weak-minded"? Seems like an awfully brittle perspective.
hypfer 22 minutes ago
TiredOfLife 3 hours ago
This line makes me think you are running a spam campaign and andrew just isn't part of it
petesergeant 3 hours ago
y-curious 5 minutes ago
ferfumarma 3 hours ago
Geezus_42 2 hours ago
ferfumarma 24 minutes ago
sureglymop 2 hours ago
If yes, regardless of who made the issues, that seems like terrible architecture/design there...
nicerice 7 hours ago
Retr0id 7 hours ago
rtpg 7 hours ago
pkulak 7 hours ago
jongjong 5 hours ago
Meta and Google can spam their unsolicited ads to a billion users but regular people aren't allowed to promote their own projects on niche forums? This is bs. You're the problem here. Self-promoting your harmful values. You're the spammer.
globular-toast 5 hours ago
hamandcheese 3 hours ago
Many projects disagree with you on this one. It is quite common to have a policy that forbids PRs without an issue or discussion first.
Sophira an hour ago
InsideOutSanta 3 hours ago
mrkeen 3 hours ago
If for some reason your services can't speak an already common language, I think it's on you to add those shims into your own project.
fy20 24 minutes ago
Let's assume that they didn't have these container restrictions and could just use an ordinary docker-compose.yml, they'd still probably want to use something like OAuth2.0 for centralised login which a lot of these services won't have.
What would be better, making a massive PR to add support for it, or opening an issue to discuss it with the maintainer first?
ErroneousBosh 2 hours ago
drunner 10 hours ago
Currently, a lot of this space is docker compose based and simply inaccessible to so many who may otherwise be interested. Whether or not it's this project or another, I hope something gathers enough steam soon to truly break the barriers to entry.
cube00 10 hours ago
Only on HN, the general public don't care, they don't even know the name of their web browser.
sevenzero 9 hours ago
vonunov 3 hours ago
myaccountonhn 9 hours ago
Fwiw I've started to see a shift in many non-tech circles I'm a part of. Especially when you take the time to explain the problems. Many do care, they just aren't made aware of the issues.
edoceo 8 hours ago
noman-land 8 hours ago
yoz-y 7 hours ago
mrtesthah 6 hours ago
It’s been around since 2010.
diggernet 5 hours ago
gitowiec an hour ago
xiaoyu2006 6 hours ago
A lumberjack may also argue GP don't care about environment laws if they had timbernews.
mystifyingpoi 4 hours ago
tonyhart7 3 hours ago
Samsung web browser uses chromium under the hood
0c3ca83 10 hours ago
ball_of_lint 8 hours ago
Also while Imbue is in some sense an AI startup it does have a very different ethos from a lot of tech companies: https://imbue.com/about
GZGavinZhao 9 hours ago
Only Gen Z and later are starting to care and willing to spend the time and effort to self host. All the Gen X and Y people that I know of, including many that are very intelligent and accomplished in their field, literally have no idea how to operate a computer outside of watching youtube, checking emails, and opening Word documents. Ads? They hate it but have no idea how to disable them. iPhone running out of storage and iCloud says I can solve that for $2.99/mo? They would be like IDK what that is but sure I'll pay that $2.99 if that means I can record more videos of my kids.
I really hate this situation, and I try my best to help out the folks around me who I see are getting ripped off (either they don't know or they know but think that's what it is). But still, it's really hard to communicate or teach those people when the skill of operating a computer has become intuition and human nature to me. I really can't put these things into words on the fly that would help them understand :(
tokioyoyo 8 hours ago
Yeah, you’ll need a lot of supporting evidence for this claim. From my personal and professional experience, this doesn’t track. And given how online the younger generations are, it tracks even less. I think there might be a bias towards tech bubbles in that statement.
ebiester 8 hours ago
xiaoyu2006 6 hours ago
I can't quite confirm that. My younger siblings' classmates (still high school students, born >=2010, non tech average people) don't give a shit on these topics and behave identical to the Gen X and Y described.
dom3k 6 hours ago
But maybe that was kind of related to times and the place – where I live people needed to be a bit more savvy, so thought like "why you buy an iPhone if Xiaomi can do the same 4x cheaper; if you chose the right model you may even have a good camera too" was popular even in non-tech circles.
But yeah, now that hardware is a bit more of a commodity and such tradeoff might give you a bit more adware with a bit less convenience, maybe it's different. But the next generation's understanding of computer/phone as something else than a magical black box is gone.
makeitdouble 7 hours ago
Building the equivalent of Google Photos locally wasn't that hard 10 years ago, given enough tolerance for speed and indexing lag issues. Trying to do the same today will cost two arms and leg and require a lot more overall knowledge of what to compose to get the same result.
The dust will settle and we should go back to a nearer gap in I hope a few years, until the. it might be a glacier age for self-hosting.
whateveracct 7 hours ago
patrickk 3 hours ago
You could argue it’s much easier on the software side, because self hosting Immich is much easier thanks for AI assistance with setting it up. If you can live without the built in facial recognition feature you don’t need particularly beefy hardware.
I find myself taking on far more ambitious self hosted projects thanks to Claude. Extending home assistant in various ways, deploying a “self hosted Spotify”, making sure everything is fully accessible via Tailscale out of the range of the wifi and so on. Of course the general population isn’t really aware or interested in most of this.
makeitdouble 2 hours ago
And it's not to fault Immich, on the contrary, Photos is one of the rare Google property where the team is constantly pushing the envelope.
I could combine it with a bunch of external tools to make do, but it would be crazy clunky or would need full sync with Adobe Cloud for instance for the editing part, while doing all the scanning and categorizing locally.
On AI assist...I'm still pausing a lot when t comes to home projects that will be constantly talking to the outside and hold the stuff that is the most private to me and my whole family and friends. It helps me as a research tool, but due to my own restrictions it won't be magic.
petra 4 hours ago
spockz 4 hours ago
Self hosting implies having hardware and software knowledge to set it up. I agree, having a meta package that would set the system up as systemd would be an even lower barrier. But then again, there are podman commands that do this for you today anyway.
Self hosting could also imply buying a device that just does this with an additional management interface for updates. This could be build around a nuc/nas with above package. It still will require some knowledge to keep it maintained.
Then, you could offer maintaining them as a service again. Maybe there is value in that.
Update: apparently there is https://freedombox.org/ which is actually an appliance for this. Although it is more privacy focused and I don’t see a productivity or photo suite on it.
creesch 3 hours ago
Because it requires people to also have knowledge about the ins and outs of docker and docker compose. If we are talking about web applications it is yet another layer that has been added over the years. It used to be that you could fairly easily host most things on a old fashioned lamp host (I am talking decades ago) and all you had to know was basic file transferring.
Of course, this was on shared webhosts in a time when VPSes were not really a thing yet or affordable. But, even on a VPS setting up a LAMP stack is relatively straightforward.
Once you add modern dockerized application to that mix you are now still looking at some sort of ingress to do the reverse proxy bit. So while it likely will not be Apache or nginx there will be some sort of layer there in addition to now having to setup docker properly (rootless and all that) and then also making sure your docker compose setup is in order.
It is not difficult *once you know how to* but it is another layer of knowledge and experience people need to acquire. That does make it less accessible for novices.
kursus an hour ago
Setting up and maintaining a server is easier today than it was decades ago, A LAMP at this time meant a lot of manual setup, IaC wasn't a thing, reproducibility wasn't a goal, versioning was confidential, documentation was scarce and often outdated, out of the box security was lower, ties to the OS were higher. Managing virtual hosts was clunky, updating OS/PHP was risky. I would not go back for anything.
> having to setup docker properly (rootless and all that)
Rootless being the proper way to setup Docker is a highly controversial take. You will mostly get added complexity and a false sentiment of security from it.
creesch 16 minutes ago
You are speeding past my point by a mile or two. With a shared webhost you get a ready lamp stack. In the late 90s early 2000s you could fairly easily get a wide array of software running that way. All you had to do is create a database in the hosters control panel, upload the package and you'd be on your way. Later in the 2000s one click installers came along for popular packages making it even easier. In fact, they are still around these days making it extremely easy to install a wide array of lamp based applications to these days.
There are very few options these days to get started as easily these days with modern non lamp tech stacks. The only thing I am familiar with (other than the product presented to us in this post) is pikapods, [which only offers a limited selection of available applications](https://www.pikapods.com/apps). There are a few others, also catalog based, though they more seem to focus on deploying on other platforms for you. Other than that you start to quickly move to more complex hosting solutions aimed at business and scaling. Or platforms that are cloud platforms with all the added complexity to navigate and figure out before you can deploy docker containers. Not to mention ridiculous situation that a few of the ones I know about have pivoted to being "agentic compute providers" whatever that means and certainly will confuse a novice. Which means that the "practical" advice given is often to "just" set up a VPS. And yes, many VPS providers will provide an image with docker enabled, but that is just the start.
> Rootless being the proper way to setup Docker is a highly controversial take. You will mostly get added complexity and a false sentiment of security from it.
That, in fact, is another layer of complexity people will then have to figure out. Most information I am aware of these days does claim that it is better to run containers rootless or at the very least make sure the user in the container is non root. The fact that we are both convinced of the opposite tells you how confusing it must be for a novice.
The overall point I am trying to make isn't even about the exact details. It is that for hosting something these days there is much more required surrounding knowledge required before you can get started in most cases.
jerf 10 hours ago
Looking at your hosted page, I see no reference to backups. I see in your docs reference to backup, but you should definitely offer some sort of turnkey, appropriately-marked-up backup solution. Configuration difficulty is what kills self-hosting on the front end, updates make it hard over time, but when it all dies and then I have no backup is when I give up.
I can't find any reference to disk size limits anywhere. Can I host Immich on this? Can I host my media server? What will it cost? Surely not $10/month for my media collection. I'm not a hoarder and mostly have stuff ripped from my personally-owned media, which limits the size, and you're still not hosting that for $10/month. I see you have Jellyfin in the set of apps but I don't know what it will cost. The CPU & RAM limits I understand from the deploy page.
Oh, and I'm specifically referring to your hosted service here.
zplizzi 10 hours ago
See docs on how this works: https://cloudinabottle.org/docs/how_it_works/data.html#the-a...
gavmor 41 minutes ago
The "workflow automation" approach is a lot of resource overhead and broker-config maintainance, but my kingdom to be able to arbitrarily compose apps' states, eg commutimemap.com + Craigslist.
0. https://www.cloudfoundry.org/technology/open-service-broker-...
1. https://github.com/gavmor/immich-concourse-resource
2. n8n.io
bob1029 3 hours ago
It often seems like presenting the image of being autonomous to our peers seems more important than actually achieving it.
It takes a lot of energy to replicate what AWS and friends have done once we factor in concerns like the passage of time and entropy. I've never been able to keep a media/NAS appliance alive for much longer than 3-4 years. Inevitably, there is some kind of catastrophic event and I have to start all over with new vendors, etc. Even without any data loss this gets old. I promise you get tired of this after a while. It might seem like that would never happen and then one day it does.
You can get so much more done if you can actually afford to use the cloud. I have a really hard time believing that many people are genuinely winning on total cost of ownership with self hosting.
hamandcheese 3 hours ago
If you are an individual and you want to store a media library, you'll go broke instantly.
I have roughly 200TB of storage capacity, 100TB used, in my NAS. That would be $2300/mo on S3 before even getting to access fees and network egress.
bob1029 an hour ago
There's no way you are consuming this much content actively. You could store all of it in S3 deep archive for $200/m (100TB) and maintain a tiny fraction in the standard resource pool.
BetterThanSober 36 minutes ago
I gave up sync and availability for sensitive data to at-rest encryption. Mundane photos/documents can stay on Google Drive, for now. I wish there's a better solution.
kolleraa 9 hours ago
I'm working on a project with similar goals but some different design decisions - instead of the typical containers I'm going for thin-client apps that hit a common data layer built on a fully serverless architecture. Not ready for production quite yet, but for those interested: https://starkeep.app/
eemil an hour ago
I'm surprised there's no such thing as a self-hosted deployment spec. An opinionated docker-compose file (or similar) with well defined inputs, outputs, and requirements that works for the average use-case.
Jnr an hour ago
Docker has poor tooling for network level security between the containers, has issues with different runtimes per container, etc.
It is just a bit primitive if you want to expose multiple services to the internet on the same server. One of those apps will get compromised and then all the others will follow.
If you want a decent self hosted server, ask your frontier LLM agent of choice to configure kubernetes (on something like k3s) with mandatory userns mapping so nothing runs as root on the host, default deny firewall so inter-container communication is as locked down as possible, and if your router supports, set up VLANs so none of the containers can access your other devices on the LAN. Use something like backrest to handle backups, alertmanager and Grafana for monitoring, Keel for auto updates. Also consider separating ingress for public and internal services and use Tailscale with split DNS to acces the internal entrypoint. Set up Crowdsec as WAF and subscribe to their free blocklists to filter out bots. Ask it to set this all up using Ansible, so it can be maintained.
While this would be extremely time consuming to set up and maintain by hand, an agent can do and test it in a few hours.
hamdouni an hour ago
crabmusket 44 minutes ago
Could you be more specific about that?
> One of those apps will get compromised and then all the others will follow...
Per their security docs, containers are rootless but I don't see anything about VLAN isolation.
skybrian 9 hours ago
Since we have AI now, I think exe.dev's pitch is better: they provide Linux VMs, a web proxy, and integrations. You can ask the AI to build whatever web app you like. I'd love to have exe.dev, but running on my Mac Mini.
dbmikus 9 hours ago
I'm working on exactly this bit (with some more tuning for messaging AI agents)
https://github.com/gofixpoint/amika
Doesn't run on your Mac Mini yet, but should get that enabled either this week or next
If you sign up (free) I'll send you an email when the "Mac Mini mode + full OSS self-hosting" is live
prologic 5 hours ago
imtringued 2 hours ago
jens_tlb 42 minutes ago
stefandesu an hour ago
Are you planning to offer alternative solutions for this, e.g. pointing a wildcard A record at the server running the instance? I'd rather not run a publicly accessible DNS server.
redrix 9 hours ago
I’m trying to self-host as much of my stuff as possible, but don’t have time to tinker like I used to. Hence updates, backups (etc) fall by the wayside in favour of “set and forget”.
klntsky 5 hours ago
utopiah 4 hours ago
cheema33 4 hours ago
nepthar 7 hours ago
yoz-y 7 hours ago
smalltorch 6 hours ago
aperrien 7 hours ago
stiray 2 hours ago
golang.
gitowiec an hour ago
silver92bullet 6 hours ago
zplizzi 6 hours ago
silver92bullet 5 hours ago
passive 9 hours ago
If you're building a personal cloud, you also want your AI connected to it, but probably with some degree of management. Aperture already provides a fair amount in this area, and probably with a connector for Cloud in a Bottle, could give your AI safe access.
hebetude 9 hours ago
tesnorindian 9 hours ago
I did a few pitches related to this at Nasscom Startup warehouse and IITM RTBI. Though this was welcomed by the panel members but it never took off due to lack of capital for such a startup during those times in India. I had to abandon and focus on my day job.
Panzerschrek 5 hours ago
These barriers are high enough, so that common people can't create/host their own sites. Only skilled enthusiasts or professionals can afford having their own site.
globular-toast 5 hours ago
Panzerschrek 4 hours ago
An unique IPv6 may be theoretically assigned to each end device and thus solve the accessibility problem for locally-hosted servers, but I doubt internet providers do this in practice and I am afraid that many providers don't support IPv6 at all.
globular-toast an hour ago
IPv6 works exactly how you describe, that's the whole point of it. No NAT, just IP addresses. Some gaming consoles use it for peer to peer multiplayer so it is in demand even by normies. One of the problems is competition is stifled in the ISP market, by monopolies and ridiculously long contracts.
harvey9 3 hours ago
_ink_ 8 hours ago
bo1024 9 hours ago
cpa 4 hours ago
28304283409234 2 hours ago
Yeah, that’s not what cloud computing is.
djohnmustard 7 hours ago