Top
Best
New

Posted by zplizzi 10 hours ago

Cloud in a Bottle: making self-hosting accessible to everyone(cloudinabottle.org)
406 points | 190 comments
KomoD 7 hours ago|
These guys have been spamming issues in repos trying to promote this project and no disclosure whatsoever that they are associated with the project.

https://github.com/search?q=%22cloudinabottle.toml%22&type=i...

mrkeen 2 hours ago||
It's evidence of bad abstraction if you need everyone else to make changes and couple themselves directly to you.

If for some reason your services can't speak an already common language, I think it's on you to add those shims into your own project.

zplizzi 7 hours ago|||
(author here) I'm checking with my team to confirm these came from us, but if so I apologize for this - posts like these should come from a real account with proper disclosure, but also these sorts of requests feel premature for a project like ours that doesn't yet have a sizeable user base.
KomoD 6 hours ago|||
The user was called adl-collab, when it forked repos to add implementations it made them under a branch called "andrew".

The biggest contributor to the project in the last 3mo is andrewlaack... and we can also just take a guess that "adl" in adl-collab is AnDrewLaak.

zplizzi 5 hours ago|||
Yeah, I'll make sure this doesn't continue. To be clear there were 11 total issues posted; this was a mistake, not some huge spamming campaign.
krelian 5 hours ago||
Thanks Andrew
jdiff 3 hours ago||
This is Zack.
dustin 25 minutes ago||
Thanks Andrew
ChrisKnott 1 hour ago|||
Possibly andrewlaack’s clanker run amok
classified 21 minutes ago||
At least this is more informative than "Thanks Andrew".
ferfumarma 2 hours ago||||
You are also characterizing another project that was open-sourced (sandstorm) and is under active development as "long abandoned". Open source is difficult and requires a fair amount of cheerleading to engage users and make them part of the community. As a result it's hard to see your project in a positive light.
Geezus_42 1 hour ago||
They also called out Sandstorm for requiring changes to the applications for them to run on the platform.
sureglymop 1 hour ago||||
Looking at the issues, do I understand it correctly that you have some way to install directly from repositories if they contain a `cloudinabottle.toml` file?

If yes, regardless of who made the issues, that seems like terrible architecture/design there...

TiredOfLife 2 hours ago||||
> posts like these should come from a real account with proper disclosure

This line makes me think you are running a spam campaign and andrew just isn't part of it

petesergeant 2 hours ago||
I used to work for this company many years ago, and it's highly unlikely they're running a (centrally organized) spamming campaign of any type. Zack's a good guy and I'm sure he'll get it taken care of promptly.
jongjong 4 hours ago|||
Why you apologise for something which is perfectly legal. Give an inch, they'll take a mile. F the authoritarians and monopolists.
hypfer 4 hours ago|||
Because "perfectly legal" and "socially acceptable" often diverge quite a bit.

The world would be quite miserable if "perfectly legal" would be what everyone optimizes for.

chii 4 hours ago|||
> The world would be quite miserable if "perfectly legal" would be what everyone optimizes for.

what you will find is that this is what corporations optimizes for. Therefore, you as a person, cannot compete with the corp.

That's why you need to become like a corp, or make the rules "socially acceptable" the same as "legal" (which is the best option).

ruszki 3 hours ago||
Yes, but first of all, people make those decisions. And second, unlike those people, you don't need to have dissonant answers, and don't need to lie to yourself.

And you can still live quite comfortably.

jongjong 2 hours ago|||
Self-promotion is encouraged in my social circles and anyone who says otherwise is weak minded so their opinions don't matter. What are they going to do about it?

They're probably jealous that they never had the guts to do it themselves and prefer to rely on friends in high places or daddy big media to promote their shit for them.

Standing behind your work is good and wholesome. Fear of self-promotion is weakness.

I often talk myself up and promote my work. Especially face-to-face. If your work actually measures up to the talk then you have nothing to apologize for. You're actually educating people and doing them a service.

Don't let yourself be bunched up with snake oil salesmen who didn't actually do the work. If you did the work and nobody noticed, then it is your duty to talk it up.

The fact that a maker can't also be a seller is dumb. You can switch modes. You have to do whatever it takes to fulfill your mission.

rexpop 32 minutes ago||
> [Behavior X] is encouraged in my social circles and anyone who says otherwise is weak minded

What is "weak-minded"? Seems like an awfully brittle perspective.

cindyllm 4 hours ago|||
[dead]
pkulak 6 hours ago|||
Hardly seems worth the pitchforks.
nicerice 6 hours ago|||
shouldn't we hold back with allegations while there's a non-0 chance this is just a user wishing their other services were supported too?
Retr0id 6 hours ago|||
I checked, it's an Imbue employee (or someone impersonating one, which seems a bit far fetched). I could could cite my sources but it feels like doxxing / drawing too much attention to the mistake of an individual. My read is that it was a separate github account that they let an agent control.
rtpg 6 hours ago|||
project literally launched yesterday... come on
ball_of_lint 7 hours ago|||
Looks like the account in question is deleted now - do you have the original username?
KomoD 6 hours ago||
adl-collab
edoceo 7 hours ago|||
It's only 11 in the last 48h, on lesser known projects.
satvikpendem 7 hours ago||
11 in 48 hours is way too many and I'd call that spam.
edoceo 6 hours ago|||
Yep, sarcasm is tough via text. Oops. I should've done /s but it's too late now.
doc_ick 3 hours ago|||
Sounds like a fun llm that’s “fixing” things.
asdf88990 7 hours ago|||
Disclosure would be nice but 11-12 issues in entire GitHub is hardly spam.
ErroneousBosh 1 hour ago|||
Tell you what though, thank you for providing such a comprehensive list of cool projects to nerdsnipe me on a sunday morning!
globular-toast 4 hours ago|||
The person doing this doesn't understand how pull requests work. The issues all say "I have a version in my fork". Open a pull request then! That's the whole point of forks on GitHub. Creating an issue first is pointless spamming akin to the classic "asking to ask". Just seems completely out of touch with open source to me.
hamandcheese 2 hours ago|||
> Creating an issue first is pointless spamming akin to the classic "asking to ask"

Many projects disagree with you on this one. It is quite common to have a policy that forbids PRs without an issue or discussion first.

Sophira 32 minutes ago||
I've never actually seen this. Can you link an example?
InsideOutSanta 2 hours ago|||
Some projects require opening an issue first.
jongjong 4 hours ago||
It's not spam if it's the first time I heard of it and it's useful. It shows they care about their project. This makes me want to try it out even more.

Meta and Google can spam their unsolicited ads to a billion users but regular people aren't allowed to promote their own projects on niche forums? This is bs. You're the problem here. Self-promoting your harmful values. You're the spammer.

gavmor 15 minutes ago||
If your "opt-in platform features" and "interface to allow permissioned access to data and capabilities between different apps" is more expressive/discoverable than eg Cloud Foundry's "Service Broker" approach[0], then I am pretty excited! I run a lot of disparate services which don't interoperate except through explicit workflow automation pipelines (I use ConcourseCI to eg upload images to Immich [1] albums, but others might use n8n[2] for the same purpose).

The "workflow automation" approach is a lot of resource overhead and broker-config maintainance, but my kingdom to be able to arbitrarily compose apps' states, eg commutimemap.com + Craigslist.

0. https://www.cloudfoundry.org/technology/open-service-broker-...

1. https://github.com/gavmor/immich-concourse-resource

2. n8n.io

drunner 9 hours ago||
I think the time for this space is here. The appetite to depart from subscriptions and loaning your personal data to ad/ai companies is stronger than ever.

Currently, a lot of this space is docker compose based and simply inaccessible to so many who may otherwise be interested. Whether or not it's this project or another, I hope something gathers enough steam soon to truly break the barriers to entry.

cube00 9 hours ago||
> The appetite to depart from subscriptions and loaning your personal data to ad/ai companies is stronger than ever.

Only on HN, the general public don't care, they don't even know the name of their web browser.

myaccountonhn 8 hours ago|||
General public is weird because everyone, yet no one, is the general public.

Fwiw I've started to see a shift in many non-tech circles I'm a part of. Especially when you take the time to explain the problems. Many do care, they just aren't made aware of the issues.

edoceo 7 hours ago||
GP typically means middle of the bell-curve. HN visitors and for sure commenters are at the edge of that curve...3-sta-nines away.
noman-land 7 hours ago||||
The general public will do whatever their friends do. If there was an iPhone charger sized box they could plug in anywhere and have their own personal cloud that can interconnect with other personal clouds, and a celebrity said it was cool to have one, the general public will do it without giving it a first thought.
gitowiec 33 minutes ago|||
There should be influencers or agitators (as named correctly) to tell general public what distro to install, what server to buy and how block tracking and ads
yoz-y 6 hours ago||||
In my experience just telling people to enable Google / Apple backup for photos is a chore at 5€ a month. And for general public this covers 90% of their needs.
mrtesthah 5 hours ago||||
You mean like this?

https://freedombox.org/

It’s been around since 2010.

diggernet 4 hours ago||
Why didn't you tell me about this years ago?
mystifyingpoi 3 hours ago||||
Precisely. My uncle has been using the builtin Samsung web browser for years on his phone, just because it said "Internet" in the name, and "Chrome" just wasn't a familiar name to him. Most people are like this.
tonyhart7 2 hours ago||
and didn't even matters tbh

Samsung web browser uses chromium under the hood

xiaoyu2006 5 hours ago||||
Digital rights are indeed important, but only a small portion of the entire concept of human rights. I can imagine general public places much more emphasis on wealth (re-)distribution policies.

A lumberjack may also argue GP don't care about environment laws if they had timbernews.

sevenzero 8 hours ago|||
True, most people get the full ad driven internet experience and it drives me nuts. Everytime I have to help other people with computer stuff I almost get an aneurysm when opening their browser...
vonunov 2 hours ago||
At some point I started just installing ABP/uBO without even bothering to ask/tell them, if I had the opportunity. So far my reads seem to have been correct regarding whether this would conflict with each person's typical web use, as I've never heard back about any trouble.
spockz 3 hours ago|||
How does being docker compose based make it inaccessible?

Self hosting implies having hardware and software knowledge to set it up. I agree, having a meta package that would set the system up as systemd would be an even lower barrier. But then again, there are podman commands that do this for you today anyway.

Self hosting could also imply buying a device that just does this with an additional management interface for updates. This could be build around a nuc/nas with above package. It still will require some knowledge to keep it maintained.

Then, you could offer maintaining them as a service again. Maybe there is value in that.

Update: apparently there is https://freedombox.org/ which is actually an appliance for this. Although it is more privacy focused and I don’t see a productivity or photo suite on it.

creesch 2 hours ago||
> How does being docker compose based make it inaccessible?

Because it requires people to also have knowledge about the ins and outs of docker and docker compose. If we are talking about web applications it is yet another layer that has been added over the years. It used to be that you could fairly easily host most things on a old fashioned lamp host (I am talking decades ago) and all you had to know was basic file transferring.

Of course, this was on shared webhosts in a time when VPSes were not really a thing yet or affordable. But, even on a VPS setting up a LAMP stack is relatively straightforward.

Once you add modern dockerized application to that mix you are now still looking at some sort of ingress to do the reverse proxy bit. So while it likely will not be Apache or nginx there will be some sort of layer there in addition to now having to setup docker properly (rootless and all that) and then also making sure your docker compose setup is in order.

It is not difficult *once you know how to* but it is another layer of knowledge and experience people need to acquire. That does make it less accessible for novices.

kursus 23 minutes ago||
> you could fairly easily host most things on a old fashioned lamp host (I am talking decades ago) and all you had to know was basic file transferring

Setting up and maintaining a server is easier today than it was decades ago, A LAMP at this time meant a lot of manual setup, IaC wasn't a thing, reproducibility wasn't a goal, versioning was confidential, documentation was scarce and often outdated, out of the box security was lower, ties to the OS were higher. Managing virtual hosts was clunky, updating OS/PHP was risky. I would not go back for anything.

> having to setup docker properly (rootless and all that)

Rootless being the proper way to setup Docker is a highly controversial take. You will mostly get added complexity and a false sentiment of security from it.

makeitdouble 6 hours ago|||
At the same time buying compute is more expensive than ever, and the gap between homemade projects and what's available online in term of speed, functionality and LLM capacity is bigger than ever.

Building the equivalent of Google Photos locally wasn't that hard 10 years ago, given enough tolerance for speed and indexing lag issues. Trying to do the same today will cost two arms and leg and require a lot more overall knowledge of what to compose to get the same result.

The dust will settle and we should go back to a nearer gap in I hope a few years, until the. it might be a glacier age for self-hosting.

patrickk 3 hours ago|||
> Building the equivalent of Google Photos locally wasn't that hard 10 years ago, given enough tolerance for speed and indexing lag issues.

You could argue it’s much easier on the software side, because self hosting Immich is much easier thanks for AI assistance with setting it up. If you can live without the built in facial recognition feature you don’t need particularly beefy hardware.

I find myself taking on far more ambitious self hosted projects thanks to Claude. Extending home assistant in various ways, deploying a “self hosted Spotify”, making sure everything is fully accessible via Tailscale out of the range of the wifi and so on. Of course the general population isn’t really aware or interested in most of this.

makeitdouble 1 hour ago||
It's about 3~4 years I haven't used Immich so it might have evolved a lot since then, but looking at their current roadmap there is a ton of features I use everyday in Photos that won't be there.

And it's not to fault Immich, on the contrary, Photos is one of the rare Google property where the team is constantly pushing the envelope.

I could combine it with a bunch of external tools to make do, but it would be crazy clunky or would need full sync with Adobe Cloud for instance for the editing part, while doing all the scanning and categorizing locally.

On AI assist...I'm still pausing a lot when t comes to home projects that will be constantly talking to the outside and hold the stuff that is the most private to me and my whole family and friends. It helps me as a research tool, but due to my own restrictions it won't be magic.

whateveracct 6 hours ago|||
for self hosted and personal use, compute lasts a good while though. and in the time you would've been waiting to time the compute market, you get to benefit by being less a part of the AI data dragnet.
petra 4 hours ago|||
Small business might care about the cost of subscriptions if they could get high quality systems this way.
GZGavinZhao 8 hours ago|||
The biggest difficulty is probably that from my observation, there's a sharp cutoff line somewhere between Gen Y and Z where anyone born before that (and don't work in tech) genuinely have no idea how to navigate their digital life and gets preyed on by those subscriptions. And these people are still a super large portion of the population paying for those subscriptions.

Only Gen Z and later are starting to care and willing to spend the time and effort to self host. All the Gen X and Y people that I know of, including many that are very intelligent and accomplished in their field, literally have no idea how to operate a computer outside of watching youtube, checking emails, and opening Word documents. Ads? They hate it but have no idea how to disable them. iPhone running out of storage and iCloud says I can solve that for $2.99/mo? They would be like IDK what that is but sure I'll pay that $2.99 if that means I can record more videos of my kids.

I really hate this situation, and I try my best to help out the folks around me who I see are getting ripped off (either they don't know or they know but think that's what it is). But still, it's really hard to communicate or teach those people when the skill of operating a computer has become intuition and human nature to me. I really can't put these things into words on the fly that would help them understand :(

xiaoyu2006 5 hours ago|||
> Only Gen Z and later are starting to care and willing to spend the time and effort to self host.

I can't quite confirm that. My younger siblings' classmates (still high school students, born >=2010, non tech average people) don't give a shit on these topics and behave identical to the Gen X and Y described.

dom3k 5 hours ago||||
Looking at my younger sister, I'd risk saying it's the same in all generations. I'll even say more: I think earlier generations had a general thought of "computer consists of separate parts; you can buy them separately and replace if needed / want better performance", even the less technical ones. But now everything is a black box (therefore e.g. why not overspend and always buy a black box from Apple if that's fashionable now).

But maybe that was kind of related to times and the place – where I live people needed to be a bit more savvy, so thought like "why you buy an iPhone if Xiaomi can do the same 4x cheaper; if you chose the right model you may even have a good camera too" was popular even in non-tech circles.

But yeah, now that hardware is a bit more of a commodity and such tradeoff might give you a bit more adware with a bit less convenience, maybe it's different. But the next generation's understanding of computer/phone as something else than a magical black box is gone.

tokioyoyo 7 hours ago||||
> Only Gen Z and later are starting to care and willing to spend the time and effort to self host.

Yeah, you’ll need a lot of supporting evidence for this claim. From my personal and professional experience, this doesn’t track. And given how online the younger generations are, it tracks even less. I think there might be a bias towards tech bubbles in that statement.

ebiester 7 hours ago|||
Or, alternatively, I was a lot more willing to put in the time to self host before I had more money and less time. If it's truly important it's not in public. If it's public, I don't have time to keep up with security patches if I'm not being paid.
0c3ca83 9 hours ago||
But this is a company building on AI.
ball_of_lint 7 hours ago||
The project itself is open source and doesn't have any AI features.

Also while Imbue is in some sense an AI startup it does have a very different ethos from a lot of tech companies: https://imbue.com/about

jerf 9 hours ago||
"We (Imbue, the company I work for) also offer a managed version, which I think is really important to making this widely accessible - and it gives us a straightforward business model to support the project."

Looking at your hosted page, I see no reference to backups. I see in your docs reference to backup, but you should definitely offer some sort of turnkey, appropriately-marked-up backup solution. Configuration difficulty is what kills self-hosting on the front end, updates make it hard over time, but when it all dies and then I have no backup is when I give up.

I can't find any reference to disk size limits anywhere. Can I host Immich on this? Can I host my media server? What will it cost? Surely not $10/month for my media collection. I'm not a hoarder and mostly have stuff ripped from my personally-owned media, which limits the size, and you're still not hosting that for $10/month. I see you have Jellyfin in the set of apps but I don't know what it will cost. The CPU & RAM limits I understand from the deploy page.

Oh, and I'm specifically referring to your hosted service here.

zplizzi 9 hours ago|
(author here) Thanks for flagging, I should make this more clear. Our managed instances have pretty small disks (~50GB), but there's a way to link a S3 bucket to your instance to use for bulk data storage. Apps that store bulk data (like immich/jellyfin) should automatically put it in the "archive data tier" which can be configured to go into this S3 bucket instead of local storage. We're planning to make this (and backups) an auto-configured part of our managed instances - billed separately (so you pay for just the additional storage you use; cloudflare R2 (S3 compatible) at-cost is like $15/TB/mo so it should be in that neighborhood).

See docs on how this works: https://cloudinabottle.org/docs/how_it_works/data.html#the-a...

eemil 32 minutes ago||
So many docker app supervisors nowadays.

I'm surprised there's no such thing as a self-hosted deployment spec. An opinionated docker-compose file (or similar) with well defined inputs, outputs, and requirements that works for the average use-case.

bob1029 2 hours ago||
There seems to be a lot of variance between stated and revealed preferences around self-hosting.

It often seems like presenting the image of being autonomous to our peers seems more important than actually achieving it.

It takes a lot of energy to replicate what AWS and friends have done once we factor in concerns like the passage of time and entropy. I've never been able to keep a media/NAS appliance alive for much longer than 3-4 years. Inevitably, there is some kind of catastrophic event and I have to start all over with new vendors, etc. Even without any data loss this gets old. I promise you get tired of this after a while. It might seem like that would never happen and then one day it does.

You can get so much more done if you can actually afford to use the cloud. I have a really hard time believing that many people are genuinely winning on total cost of ownership with self hosting.

BetterThanSober 10 minutes ago||
Yep, even with something like NextCloud or ownCloud it gets tiring pretty fast. I do get the appeal of handling everything on your own, but it also brings any of the downside of handling everything by myself. I just need a working cloud storage with sync, redundancy, and availability. Can I get it up to spec? Definitely but it will cost more both in time and money than getting OOTB solution.

I gave up sync and availability for sensitive data to at-rest encryption. Mundane photos/documents can stay on Google Drive, for now. I wish there's a better solution.

hamandcheese 2 hours ago||
> if you can actually afford to use the cloud.

If you are an individual and you want to store a media library, you'll go broke instantly.

I have roughly 200TB of storage capacity, 100TB used, in my NAS. That would be $2300/mo on S3 before even getting to access fees and network egress.

bob1029 46 minutes ago||
How are you backing up 100TB of data? Have you factored the consequences of catastrophic data loss into the economics? How much value would you lose if all your data was gone?

There's no way you are consuming this much content actively. You could store all of it in S3 deep archive for $200/m (100TB) and maintain a tiny fraction in the standard resource pool.

jens_tlb 16 minutes ago||
Your headline is literally the slogan of Magic Cloud. It's been around since 2019, and does this "exact thing" - Basically, "your cloud, on premises" ...
kolleraa 8 hours ago||
This is a great project! Yes, the personal cloud is coming and it's going to be for everyone.

I'm working on a project with similar goals but some different design decisions - instead of the typical containers I'm going for thin-client apps that hit a common data layer built on a fully serverless architecture. Not ready for production quite yet, but for those interested: https://starkeep.app/

Jnr 30 minutes ago||
In the age of LLM agents, still going for Docker/Podmam on anything besides local development box seems like a weird choice.

Docker has poor tooling for network level security between the containers, has issues with different runtimes per container, etc.

It is just a bit primitive if you want to expose multiple services to the internet on the same server. One of those apps will get compromised and then all the others will follow.

If you want a decent self hosted server, ask your frontier LLM agent of choice to configure kubernetes (on something like k3s) with mandatory userns mapping so nothing runs as root on the host, default deny firewall so inter-container communication is as locked down as possible, and if your router supports, set up VLANs so none of the containers can access your other devices on the LAN. Use something like backrest to handle backups, alertmanager and Grafana for monitoring, Keel for auto updates. Also consider separating ingress for public and internal services and use Tailscale with split DNS to acces the internal entrypoint. Set up Crowdsec as WAF and subscribe to their free blocklists to filter out bots. Ask it to set this all up using Ansible, so it can be maintained.

While this would be extremely time consuming to set up and maintain by hand, an agent can do and test it in a few hours.

crabmusket 18 minutes ago||
> has issues with different runtimes per container

Could you be more specific about that?

> One of those apps will get compromised and then all the others will follow...

Per their security docs, containers are rootless but I don't see anything about VLAN isolation.

https://cloudinabottle.org/docs/how_it_works/security.html

hamdouni 26 minutes ago|||
Skip kubernetes and deploy to bare server
stefandesu 34 minutes ago|
> 53 is required because instance runs its own authoritative DNS server.

Are you planning to offer alternative solutions for this, e.g. pointing a wildcard A record at the server running the instance? I'd rather not run a publicly accessible DNS server.

More comments...