12 comments

  • smashed 18 minutes ago
    I can relate to the TLS termination issue. It is difficult to provide a self hosted version of a web app with a sensible TLS setup.

    The best is almost not to do it at all. Just have a docker image serve http/1.1 and document that a reverse proxy is required to expose the service.

    There are simply too many ways to do it and every sys admin/hobbyist has their own preferred way.

    For the anonymous and authenticated caching issues the author goes into, I think once again it is useless for self hosting. Just embed a performant web server like nginx for example that is pre configured to serve static files. Use proper headers, and predictable/simple paths. Self-hosted versions are going to be low traffic and just need to work.

    Have advanced settings for more control, but keep the default simple and working out of the box with minimal dependencies.

  • glaslong 4 minutes ago
    I literally just sent some friends a docker image and told them to point Luna at it, for which they were set up in ~20minutes and $3 of tokens, so I'm skeptical.

    My homelab is also currently ~40 nix service VM's plus a handful of Ubuntu, etc long tail, and some external DO droplets for NAT, and a more robust vlan config than I'd ever been able to put time towards before... which I haven't had to do more than a dozen hours of manual setup on IN TOTAL thanks to Fable, Sol and local Qwen.

    There's truth in this post, but I doubt it's longevity.

  • lee_ars 16 minutes ago
    > You document what needs to be reverse proxied and give examples for caddy and nginx, repeatedly cursing at nginx for not having an if that’s useful.

    Somebody hasn't read the docs and doesn't understand how nginx's "if" works, because it's fantastically useful.

  • ComputerPerson 1 hour ago
    I host a webserver for a living, so I might be too far removed from the problem; I don't see anything that 1 minute of effort as part of a less-than-10-minute session with an agentic AI tool can't solve safely. A decent README and project structure is all Codex/CC/Pi needs. I mean this even for the least-technical person who would be self-hosting something.

    I guess that breaks the plug-and-play nature, but you can't expect something internet-facing to be plug-and-play. (Maybe that's the real travesty here.)

  • bradly 50 minutes ago
    I'm not sure I understand this post. Is this talking about self hosting Caddy in a home lab setting or just static web hosting on a VPS?
    • deltarholamda 19 minutes ago
      It's partially about how complicated modern Web services can be, and why so many people just give up and ship a Docker container. It's also about how agonizing over the details is sometimes just wasted because all of your users are just AI scrapers.

      An art professor I knew used to say about overwrought paintings "too much sugar for a dime". Technical people are often prone to this as well.

    • tingletech 18 minutes ago
      I think the author is distributing a web app that is run by hobbyists with a lot of esoteric home labs?
    • sam_lowry_ 48 minutes ago
      I think the author missed the root cause, which is the demise of (unencrypted) HTTP/1.1 connections.
  • KronisLV 25 minutes ago
    > Deployments not using Docker will no longer be supported.

    This is the way (while also allowing people to use their own proxies etc., but being clear about those not being officially supported).

    Ship your back end container, your front end container, tell people how to set up the off the shelf DB containers or whatever else your software needs and if you don’t need 20 different components like Sentry self-hosted versions do, you’ll be fine. The DB can be a container or not. The reverse proxy can be a container or not. Hell, if someone wants to build the back end or front end from source and serve them differently they can, just on their own time. That’s pretty close to the 12 Factor App principles.

    Just avoid a lot of complexity when possible: do traditional SSR, or with some progressive enhancements or what I like to do in this day and age (unless maximum accessibility is paramount) only use your back end for the API and have a traditional SPA, none of that complex Next.js stuff. Your front end just becomes a bundle of files that you can put in a web server container to be proxied by whatever the ingress is. At most the Docker entry point would change some values in config.json that the app loads on startup in the browser.

    If someone asks for Kubernetes support or whatever, just wish them the best of luck in setting it up themselves!

  • Dotnaught 49 minutes ago
    Perhaps the article's title should be, "The web has become a hostile, largely automated environment and naive hobbyists may find it difficult to coexist with professional scrapers, scammers, grifters, bots, hucksters, and cybercriminals."
  • sam_lowry_ 51 minutes ago
    This is only tangentially related, but I have a love-hate relationship with Immich. Love for everything, but loads of hate for the bug-o-feature that disallows sharing of albums if the website is not hosted over HTTPS.

    I can fiddle with the page content in Developer Tools to make it work, but frankly, WTF, especially since Immich expects people to set up a reverse proxy for HTTPS access on their own and does not help them in any way (like providing a pre-configured caddy in their compose.yaml, I don't know)

    • AussieWog93 32 minutes ago
      Honestly, this is a problem that has been solved by LLMs. Just point Claude Code to the server over SSH and say "We need Immich to be served over HTTPS".

      You could theoretically upstream the fixed compose.yaml if you felt like it, but the project seemed unusually hostile towards the one fix I tried to upstream.

  • scotty79 56 minutes ago
    How many of these problems PHP solves out of the box or makes irrelevant?
    • tommek4077 48 minutes ago
      All. People forget hiw performant the LAMP stack is.
    • vehemenz 30 minutes ago
      It feels like there could be an entire longform piece on how "modern" web development norms arose because hobbyist/student web developers learned everything in an ad-hoc, local environment without access to, you know, a development server or a mature software stack.
  • hn5xz7plcj 28 minutes ago
    This is quietly brilliant
  • skydhash 41 minutes ago
    All of those requirements seem weird. I selfhost a few software and the user count is one. My extent at sysadmin is to write a systemd service, configure the proxy (if it’s on a vps and I use subdomains), and maybe use ansible for scripting the provisioning and deploy.

    It’s fine to publish recommendations how to tune configurations for specific usages. But I only need the app, not the various things that you may think I need. And I really want the app to only solve its essential problem. It should not take care of the IT part other than providing configuration samples.

    • jermaustin1 28 minutes ago
      And I do `docker compose up` now with a caddy server in front of docker, so I can just add a new site (sub domain or directory) that reverse proxies to that docker container's port. And the beauty is, that I have a skill for it for claude code, so I actually don't have to do any of that for my local self-hosted stuff.

      I just call /publish-local-docker subdomain.mydomain.local

      And if there isn't a docker compose, it will create one, and then run it, and update caddy server on its own.

  • jdw64 9 minutes ago
    [dead]