I’m just using regular Nginx, which I’ve been using for 20 years. What does Nginx Proxy Manager or npmplus do better?
I’ve been meaning to try Angie too, which is a fork of Nginx.
Aussie living in the San Francisco Bay Area.
Coding since 1998.
.NET Foundation member. C# fan
https://d.sb/
Mastodon: @dan@d.sb
I’m just using regular Nginx, which I’ve been using for 20 years. What does Nginx Proxy Manager or npmplus do better?
I’ve been meaning to try Angie too, which is a fork of Nginx.
Caddy is a good piece of software.
I’ve been using Nginx for 20 years and don’t really have a reason to switch, so I’m still using it. I use certbot, so it’s just one command to create the certificate initially, and then it auto-renews automatically via a systemd timer.
A private key leaking is bad, since anyone with the private key can decrypt data that was encrypted with it.
Traditionally, the way that leaked certs were handled was via Certificate Revocation Lists (CRL). CRLs contain lists of revoked certificates - their serial number, revocation date, and the reason why they were revoked.
However, CRLs are imperfect. Checking for revoked certificates every time you go to a site would slow things down a lot, as the lists are now too large to check and download real-time. Modern browsers and other TLS clients periodically download the lists in the background. Also, it might take a while between when the certificate is compromised and when the company notices the compromise.
Because of this, the CA/Browser forum (a group with all the major browser and TLS certificate vendors) have started dropping the max lifetime of certificates. The idea is that even if a private key does leak, the time frame that it’s usable for will be significantly shorter and any leaks should (in theory) cause less damage.
All modern deployments, regardless of if they’re using free or paid certs, should have their renewals fully-automated, so in theory the validity period shouldn’t matter as much as it did in the past. All major vendors (Let’s Encrypt, DigiCert, Sectigo, GlobalSign, AWS, SSL .com, etc) support ACME now. Reducing the validity is also a forcing function t o ensure automation is actually implemented.
somehow else in the middle and just can “ignore” certs renewals?
I’m not sure that’s possible, since an attacker in the middle shouldn’t be able to obtain a valid certificate for the domain. Certificates have a “not valid after” date encoded into them, after which the certificate is considered invalid and you get an error.
I’ve already got solar panels on my roof. Originally they fully covered our usage, but my wife and I have two EVs now (a BMW iX and an i4) and charge them at home, so we’re back to having to pay the electricity company.
I’ve got 1:1 net metering (grandfathered into an old plan) so don’t need batteries.
Makes sense! 30W is great for your system. My home server has an older 10Gbps NIC that uses an Aquantia AQC107 chip, which has poor support for ASPM and prevents the CPU from entering lower C states. I’ve been considering swapping it out for something newer (like an AQC113), I just need to work out whether it’s actually worth it.
Mine used to cost $0 in electricity since I’ve got solar panels, but we’ve got two EVs now (my wife has a BMW iX and I’ve got an i4) so we’re back to having to pay the electricity company again.
Creating a cluster could help me self host more websites I create as I want to move away from using hosting services
Just jeep an eye on electricity prices. This is probably not an issue with a phone server, but for me, hosting at home with a decent server PC costs more per month just in electricity compared to using a cheap VPS. Continuous draw of 50W 24/7 is ~37kWh per month which can cost $15 or more in California.
I do still host some things at home, but all my sites are on VPSes. The enterprise hardware and fast, data center grade internet connection is worth it for me. Some of my VPSes are only $40/year.
A friend is running Linux, Nginx, Hermes Agent, and a few other things on her old phone. Definitely doable! It’s a decent idea - very small form factor, phones have pretty powerful CPUs, and a lot of people have an old phone they’re not doing anything with.
I’m not sure about the Note, but the Samsung Galaxy S series phones have an option to limit charging to 85%.
Cycling the battery is a good idea too though. I used to do that with a wall mounted tablet and a smart plug, until I swapped it for a Lenovo tablet that has this as a built-in feature


Definitely true. The Pi 5 is especially powerful compared to older versions, but it can get kinda expensive once you add things you’d want for a server, like a case, SSD hat, etc.
Ex-office mini and small form factor PCs (Lenovo Tiny/ThinkCentre, HP ProDesk/EliteDesk, Dell Optiplex, etc) can be a better deal than a Pi. In the US at least, you can often find 9th or 10th gen Core i5 systems for less than $150 on eBay. Works great as a server.
A lot of companies have a 3-4 year refresh cycle, after which the hardware is fully depreciated (essentially meaning its value to the company is $0) and they have e-waste companies collect them. The e-waste recyclers test them, refurbish the ones that still work, and list them on marketplaces like eBay.


I forgot to mention - stay far away from SSDNodes. Their prices look good, but they massively oversell their RAM. They use ballooning (virtio_balloon) to overallocate RAM, and require you to use their customized Linux distro images that have it enabled. Ballooning means that they take unused RAM from your VM and lend it to other VMs to use. If you try to use all your RAM, they shut down your VPS.
GreenCloud, HostHatch, and RackNerd all let you install whatever OS you want, by mounting an ISO, connecting to the VPS via VNC, and going through the normal setup process just like you would on a regular computer. They do have pre-built images, but I always prefer to install from my own ISO so I know that the installation doesn’t have any non-standard modifications.
Thankfully, most VPS providers don’t oversell RAM or disk space.


My guess would be renting a dedicated server, or a home server. It can end up cheaper than colo.
self host?
Hosting at home, renting a dedicated server, or colocating are all considered self-hosting.


They’re reliable, but overpriced for what you get, especially after the Akamai acquisition. Akamai are not known for affordability :)


I use GreenCloudVPS for a bunch of things. They used to have VPSes starting at $15/year for 2GB RAM and 20GB disk, but their current budget deals are still good (starts at $25/year for 4GB RAM and 35GB disk). These are on older hardware (mostly AMD EPYC Rome Zen 2 systems, ~5 years old) which is why they haven’t been affected by increased RAM and storage prices yet. https://greencloudvps.com/billing/store/budget-kvm-sale
They also have “premium” plans which are newer (AMD EPYC Milan Zen 3 or Genoa Zen 4, and PCIe 4.0 NVMe storage in RAID10): https://greencloudvps.com/billing/store/premium-kvm-sale
HostHatch is good too. Their regular pricing aims to compete with Hetzner, but in 13 locations worldwide. https://hosthatch.com/products. They do sometimes have sales on LowEndTalk with pricing similar to GreenCloud’s “premium” plans.
RackNerd sometimes have good deals, although they’ve discontined quite a few of them recently. You can use https://racknerdtracker.com/ to see currently active deals. I still see a 2GB RAM + 35GB storage deal for $35/year for example.
I suspect all the very cheap ones (<$50/year) will eventually increase pricing. GreenCloud and HostHatch own all their hardware. Right now they use older hardware that’s already reached break-even, but all hardware needs to be replaced eventually, and the replacement cost for things like enterprise SSDs is a lot higher than it was in the past.
If you want to stick to big names, OVHcloud and Hetzner both have pretty good VPS pricing. OVH runs theirs on very old hardware like Haswell (2014/2015 era) Xeon E5 CPUs which is the main reason why they have cheaper pricing that Hetzner.
There’s also AWS Lightsail that’s essentially Amazon’s version of a VPS. Storage and data transfer are included in the monthly price, unlike EC2 where it costs extra. I’d only use it if you like AWS or want the comfort of using a very big company though - performance is notably worse than a provider like GreenCloudVPS or Hetzner.
I’m not affiliated with any of these companies. This is just my personal experience :)


I wish more modern TPUs were available for purchase. Google’s TPU v8i is very powerful, but you can only rent it via Google Cloud. (that and they’re most useful in big clusters, and the pricing for such a cluster is definitely out of reach for anyone that’s not running their own data center)


For small options, there’s mini PCs with the AMD Ryzen AI Max+ 395, and the Nvidia DGX. Their memory bandwidth is quite low compared to a GPU though, so expect slower performance.


Do you want to run TensorFlow Lite / LiteRT models? PyTorch Mobile? TensorRT? onnx? YOLO? vLLM? Something else? The recommendations will vary based on your use case.
Google Coral was decent for TensorFlow Lite, but it’s EOL (end of life) now. I’ve got the dual TPU Mini PCIe version in my home server, via a PCIe adapter board. I use it for object detection with Blue Iris + CodeProject AI and it works pretty well for that use case.
Hailo-8 is supposed to be like a more powerful version of the Coral, but I don’t have experience with it. It supports a bunch of frameworks: TensorFlow, TensorFlow Lite, Keras, PyTorch and ONNX. I’d be interested in hearing other people’s thoughts on it.
I don’t know if any of these work over USB though. They’re usually internal devices. Google marketed the Coral USB as being for development and testing only, pointing people to the M.2 and PCIe versions for production usage.
As for something totally different… There’s the Nvidia Jetson single board computer which supports TensorRT, but I don’t have experience with it either. I also think it’s a bit older too. You could also consider getting a newer mini PC with a AMD Ryzen AI processor in it, or an Nvidia DGX Spark.
Google’s latest TPUs are only available in their cloud - they’re not selling the hardware to end users any more.


And I don’t ever know if it’ll get better because you need to know why you want to build something someway.
The major issue I’m seeing with junior (and even intermediate) developers is that they trust that the AI will always do things the correct way and don’t question its approach, and they don’t develop proper debugging skills and just rely on the AI to attempt it.
To get decent quality output out of an AI model, you need to have critical thinking skills, at least basic knowledge of the overall architecture for whatever you’re trying to build, and enough knowledge to question the model when it does something wrong.
Blindly trusting AI is why so many old security issues are coming back - stored/reflected XSS, SQL injection, exposing databases directly to the internet with no password, things like that. Newer frameworks mostly got rid of them, and now AI is bringing them back. It’s a fun time for red teams at least.


Does Patchmon not have a setting to look for the Docker socket in a different location?
I could be wrong but I don’t think there’s any security issues making a symlink to a socket, since permissions/ACLs on the socket would still apply.


My Epyc 7702 does have onboard TPM, but my supermicro H11DSi-NT doesn’t pass it through to the OS, for some reason
Huh… That’s interesting. At my workplace we have Linux EPYC servers with working TPM (it’s mandated that all computers, both clients and servers, must have TPM 2.0), but I’m not a hardware person and don’t know exactly how they’re configured.
Makes sense! I didn’t realise it has a UI.
I’ve got a bunch of snippets in
/etc/nginx/snippets/, so for example I just need to addinclude snippets/proxy.confto a server block to add most of the configuration needed for a reverse proxy. I’ve been using Nginx for long enough that I just write the rest of the server block by hand.