Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I've been running OpenBSD on DO for years. I have a very details guide about setting up iked just in case you are interested: https://ngxv.org/blog/entry/2021/01/14/openbsd-vpn

    P/S: The website is running on a Raspberry Pi 3 in my house, hope HN won't hug it to dead

  • Crazy that after so many years of cloud compute a 8GB VM is $48/mo.
  • If you can, it really makes sense to look for low cost dedicated servers. For $35/month I get a whole machine with dual L5520 and 24 GB of ram. I used to have a little nicer server for a little less, but that provider had to close because their costs for electricity and space went up too fast. Yes, the L5520 is ancient, but my server needs are tiny and it's fun to have a whole machine.

    Look on webhostingtalk or lowendbox or lowendtalk.

  • Does DigitalOcean still only propose up to 4 basic cpu as droplet maximum ?. All their compute capacities disappeared overnight 2025/2026 without any reason.
  • I heard all the RAM scheduled to be manufactured next year had already been sold out. Maybe that's a related phenomenon?

    https://news.ycombinator.com/item?id=49207236

    e.g. Hetzner tripled prices recently.

    https://news.ycombinator.com/item?id=48542064

  • Back in my day a blog post like this would've included a promotional link for $100 in DigitalOcean credits!
  • Now DO has to plow those loss-leading Marketing dollars into paying for memory I expect...
  • I run OpenBSD at netcup.de for €2/month. It's very low-spec, but it's enough.
  • You can even go completely free with Cloudflare tunnel with your own office/home hardware. I have a simple web running on my old Raspberry Pi 3 + nginx + golang web app. Also with ssh access to the Pi.
  • You still have to pay for electricity. If you consider that "completely free" then paying $4 per month should also be considered "completely free".
  • You don't even need your own hardware. You can serve your site using the free CF Workers plan. Of course, that's a different goal than running bsd in an aggressively tiny cloud instance.
  • I've thought about this as well but I was not too comfortable with it.

    As I understand it it is a reverse tunnel from your internal network to cloudflare? If your device is compromised it may lead to an attacker using that tunnel to access your internal network through the host device?

  • Yes, the cloudflare SSH tunneling works well -- though I think the fact that SSL is provisioned means it'll show up in the cert transparency log, possibly attracting unwanted attention to probe my home systems.

    I ended up turning that off and switching to Tailscale. Tailscale is set to advertise my home IP range (I chose one that's not 192.168 based which avoids problems with range conflicts). So I can just connect to Tailscale and connect to 10.X.Y.Z as though I'm home. If I want memorable hostnames I can point DNS records to those private IPs.

    by xp84
  • DO burned me recently due to their unwillingness to handle DDOS attacks: "The best we can do is change your IP." Thanks guys.

    Switched to OVH immediately.

  • I migrated a client off for the same reason. The “app platform” ran behind Cloudflare, but they run the Cloudflare, so I couldn’t put it behind my own Cloudflare, nor could I configure it and solve the problem. Moved the entire thing to Hetzner, fast. What a week.
  • They're also too stupid to understand that they've been dropping UDP datagrams with src port == dst port and < 1024. This obviously breaks IPsec IKE. I showed them dummy traffic captured with netcat and tcpdump, but they refused to admit they caused the problem. They repeatedly claimed to see nothing dropped between the pcap files, that I was doing it to myself with a firewall that wasn't even enabled, or that this is just how a network is supposed to work.
  • A warning sign indeed for long time users of DO. Their marketing basically says "yes, we handle those".
  • I tried to warn them that they were hosting a phishing site once and they weren't very receptive.

    Otherwise, I hosted a site with them for years and all went well.

  • For a little bit more you can rent on https://openbsd.amsterdam - they also donate to the OpenBSD foundation!
  • +1 for obsd.ams , great VPS!
  • Man I always look at this project with nothing by awe. I'd love to start something like this... if you're in central Switzerland and would like to copy their model, hit me up.
  • They are cool, man they've grown. I used that when there were ~20 VM's on there. Its a great project but think its only physically in Amsterdam which is why I ended up moving back to vultr, as they have many more options.
    by 8by3
  • Great service for small personal blog or a testbed. OpenBSD has httpd + acme client for SSL termination & automated rotation so the base system has just enough to host a low traffic website. For anything that requires uptime one will have to buy multiple VMs and handle the uptime story themselves, since they go down regularly for maintenance.

    The fact that they donate back to OpenBSD is great though. I own a VM there for testing stuff.

  • openbsd.amsterdam is notable because they use the openbsd native vmm as the vm host. It is obsd all the way down over there.

    It is a small and no frills service but the sys-admin, who runs the project, is very helpful and attentive. That is to say probably much better and human customer service than the big players. There are definite downsides, but if a project fits, highly recommended.

  • I've always gone with Vultr (vultr.com) for BSD VMs, its properly supported by them and while I've never hard verified this, they seem like a nice smaller player. Like they have offered Open/Free BSD VM's for > 10 years, kind of nice.
    by 8by3
  • They were very helpful when one of the AMD firmware patches in 7.3 caused my VPS to not boot. They even offered to apply a manual fix until patch -015 was available which fixed it.
  • The admins have access to your data and unless things have changed, that isn't monitored. They also bend to NSLs like any other provider. What they charge vs what things cost hurts.
  • I used buyvm.net for BSD a while back. Didn't have any issues, and the few times I contacted their support they were quick to respond and helpful.

    rootbsd.net before that, but they don't seem to exist anymore.

  • I have a couple of FreeBSD VMs on Vultr. For quite some time sshd regularly dies on one of them and I am not sure why.

    A couple of theories I’ve had is that maybe

    a) my VM was compromised and there is a persistent rootkit installed that kills sshd, or

    b) file corruption after previous unclean shutdown has left some file needed by sshd corrupted and it leads to this behaviour, or

    c) maybe it’s running out of memory sometimes

    Each time I want to ssh into the machine I usually have to first connect with the VNC from the vultr dashboard to start sshd up again.

    It’s running the latest FreeBSD, as every now and then I log in and do an upgrade on it some time after a new version has been released.

    A persistent rootkit may have been installed if it was compromised between when some vulnerability became known and when I later upgraded next time.

    If a file was corrupted in an unclean shutdown in the past maybe it’s a file that has not been changed between FreeBSD versions so even though upgrades replace some files maybe it’s the same corrupted file all along.

    Ideally I’d just reinstall the machine, but that’s always more of a hassle than it should be so I continue running the VM in this broken state where sshd keeps dying every now and then.

  • I remember when Vultr was new and had a single rack with a handful of boxes. Their site has no graphics apart from an ASCII logo. They had low prices but you often had to wait for them to build a new box before you could sign up. Their whole schtick at the time was, "we are building this for people who know what they are doing, don't bother us for support, we don't have any."

    But they are not that small anymore. They are now VC-funded, operate in 36 datacenters worldwide and are currently spending $1 billion to build an AI datacenter in Ohio.