I'm now VPS red pilled (and protecting with CloudFlare)

แชร์
ฝัง
  • เผยแพร่เมื่อ 14 ธ.ค. 2024

ความคิดเห็น • 381

  • @joshrogan3577
    @joshrogan3577 9 หลายเดือนก่อน +160

    Babe wake up the daily Web Dev Cody DDOS video just dropped

    • @kathenae
      @kathenae 9 หลายเดือนก่อน +3

      😂😅

    • @SeibertSwirl
      @SeibertSwirl 9 หลายเดือนก่อน +8

      Oh god I hope this doesn’t become a daily thing, I will have to start up an onlyfans 😅

  • @algobuddy
    @algobuddy 9 หลายเดือนก่อน +66

    Switching to a VPS with Cloudflare for DOS protection sounds like a smart move to avoid hefty charges. Your step-by-step guide makes it much easier for others to follow suit. Appreciate the insights!

    • @redetermine
      @redetermine 9 หลายเดือนก่อน

      Chatgpt ahh comment

  • @rodjenihm
    @rodjenihm 9 หลายเดือนก่อน +138

    Next step: hosting everything on Raspberry PI 5 in your room.

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +16

      Let’s go!

    • @PASTRAMIKick
      @PASTRAMIKick 9 หลายเดือนก่อน +1

      unironically yeah

    • @tanko.reactions176
      @tanko.reactions176 3 หลายเดือนก่อน

      you really only need to pay for a domain name.

    • @rodjenihm
      @rodjenihm 3 หลายเดือนก่อน

      @@tanko.reactions176 And static IP address.

    • @BhargavSushant
      @BhargavSushant 3 หลายเดือนก่อน

      Self hosting is the way

  • @AnteZivkovic
    @AnteZivkovic 9 หลายเดือนก่อน +294

    Digital ocean DDOSed you because of your "Why I'd never host my apps on a VPS" video.

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +36

      probably 🤣

    • @AndrieMC
      @AndrieMC 9 หลายเดือนก่อน +6

      isnt aws vps stuf

    • @yassine-sa
      @yassine-sa 9 หลายเดือนก่อน +2

      Makes sense it's their style

    • @Lostlabs
      @Lostlabs 8 หลายเดือนก่อน

      Just get a ddos protected VPS from OVH, Path you can find providers easily. (Ex. Vibegames path) Which will basically make the server not be able to be hit on L4 and also better specs then Digital Ocean.

    • @3ventic
      @3ventic 8 หลายเดือนก่อน

      @@AndrieMC if you use AWS for VPS (ec2 as they call it) alone, you probably shouldn't be using AWS.

  • @dr.lazysloth3415
    @dr.lazysloth3415 9 หลายเดือนก่อน +51

    I don't know why anyone would waste time DDOSing your system. You're just a nice guy posting fun educational videos. I am probably to lazy to come up with a reason.

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +21

      sometimes a DDoS attack is just random; someone finds an open machine after scanning ip addresses and attacks it; but yes this seems targeted 🤣

    • @dr.lazysloth3415
      @dr.lazysloth3415 9 หลายเดือนก่อน +2

      @@WebDevCodyye maybe it's just random but it feels targeted from your point of view. It does increase the potential revenue of amazon or cloudflare which might benefit the attacker. Don't know if you can just change the IP..

    • @rahultech77
      @rahultech77 9 หลายเดือนก่อน +22

      Dude I feel the attacker wants to DDos protect their app, so wants a tutorial from Cody for it 😂

    • @dr.lazysloth3415
      @dr.lazysloth3415 9 หลายเดือนก่อน

      @@rahultech77 that’s probably it 😆

    • @JamesJGoodwin
      @JamesJGoodwin 8 หลายเดือนก่อน

      Hackers and script kiddes (especially) loves attention

  • @Kay8B
    @Kay8B 9 หลายเดือนก่อน +60

    If its just for side projects, its a lot easier having your service go down and just rebooting it all back up rather than paying a hefty bill. Cloud is strictly for high traffic businesses in my opinion. Plus you learn so much more setting up your own VPS and securing it yourself.

    • @rand0mtv660
      @rand0mtv660 8 หลายเดือนก่อน +5

      True. I think it's great knowing how to run a node/go/whatever app and setup nginx or caddy to proxy to it. You realize how much you can do and what problems those managed services actually solve for you.
      Also in some enterprise cases you cannot just deploy to whatever cloud service and must deploy on premises or are potentially only allowed into VMs so having this knowledge is beneficial.

  • @JonnyJKF
    @JonnyJKF 9 หลายเดือนก่อน +20

    If you are using a VPS you should set it up to reject all connections except HTTPS coming specifically from Cloudflare's IP ranges (and ssh traffic if you don't have another console available).

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +5

      thanks for the suggestion, I ended up adding that today as well

  • @markshinkai598
    @markshinkai598 9 หลายเดือนก่อน +17

    This is starting to be a series, But this content is very real and educational

  • @lifewithyousof
    @lifewithyousof 9 หลายเดือนก่อน +7

    This is wild, thank you for sharing these videos with us. Happy to see you got things resolved!

  • @xemronn2303
    @xemronn2303 8 หลายเดือนก่อน +3

    Great content, your DDOS protection series are basically showing a process how human being is learning from it's own mistakes :D Hopefully it will save some money for others too!
    One tip from me, you can move this push-image script to a github action, that will build and push image to ECR automatically on every push to master(or only when you manually trigger it). This way you will have kind of automated CD pipeline for your project. GH actions are also free up to 2k run minutes per month making it a decent solution for hobby projects

  • @neociber24
    @neociber24 9 หลายเดือนก่อน +14

    I had some hobby projects on AWS, and is scary that any error or DDOS can give you a 2000$ bill.
    Paying 5$ dollar a month for a VPS for projects that make no money is better than being worry about that.

  • @codehighlights
    @codehighlights 8 หลายเดือนก่อน +3

    Love how he learned and changed totally the argue that we should host everything on managed services like cloudfront, vercel, netlify etc instead of doing custom VPS setups. :)

    • @WebDevCody
      @WebDevCody  8 หลายเดือนก่อน +6

      😆 a $1,500 bill created in a few hours will do that to a dev

  • @jose6183
    @jose6183 9 หลายเดือนก่อน +6

    Thank you for sharing this! These couple of videos have been really useful. Great content

  • @stevanfreeborn
    @stevanfreeborn 9 หลายเดือนก่อน +3

    Thanks for sharing how you are working through this situation. I'm though really sorry about the AWS charges. That just sucks. I'm hoping their understanding and helpful about a credit or refund.

  • @xyssxy
    @xyssxy 9 หลายเดือนก่อน +16

    You definitely want to make sure to block all incoming traffic on port 443 and 80 except for cloudflare ips in a firewall like ufw on the backend server. If you dont do that, crawlers will be able to resolve your domain to your backend ip, leaking the ip, bypassing any cloudflare protection.

    • @groff8657
      @groff8657 8 หลายเดือนก่อน

      If you proxy to your website using CloudFlare DNS, how do you know those IPs? Are they listed somewhere, is there documentation that lists all those IPs?

    • @xyssxy
      @xyssxy 8 หลายเดือนก่อน

      @@groff8657 There are websites & tools to scan pretty much the entire web, if you render your pages on ips too, or have any correlations to your domain, they will be able to link the ip back to the domain

    • @twitchizle
      @twitchizle 8 หลายเดือนก่อน

      ​@@groff8657there are 255^4 ips in the world. Its not so hard to crawl all of em

    • @xyssxy
      @xyssxy 8 หลายเดือนก่อน

      @@groff8657 Yes there is, just type cloudflare ips in any search engine

    • @Lucas-qr7ul
      @Lucas-qr7ul 8 หลายเดือนก่อน

      @@groff8657 It's in cloudflare docs. You can google and you'll find it.

  • @DaviMartins99
    @DaviMartins99 8 หลายเดือนก่อน +1

    VPS, Caddy, Digital Ocean, docker-compose...
    Let's go, Cody! This is the way!

  • @OetziOfficial
    @OetziOfficial 9 หลายเดือนก่อน +2

    Can't wait for SST ion to have all of this ready :) I don't want to use docker stuff, that hustle annoys me a lot. Way to much effort.
    Preferably with SolidStart (and Protection enabled)

  • @Dom-zy1qy
    @Dom-zy1qy 9 หลายเดือนก่อน +6

    But why would someone DDOS you ?? You're the chillest dude on web dev yt

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +14

      Because there is a lot of room in hell and someone is reserving their slot

    • @real23lions
      @real23lions 9 หลายเดือนก่อน

      @@WebDevCodyI’m stealing this answer 😂

  • @darrenhinde2971
    @darrenhinde2971 9 หลายเดือนก่อน +1

    Thank you for sharing all these videos, been insightful especially as I am looking to move from Vercel to AWS and some of these issues I never thought of.

  • @parkerrex
    @parkerrex 3 หลายเดือนก่อน

    This is a great video - got VPS red pilled by Levels' on the Lex show. Thanks for uploading!

  • @namtrg
    @namtrg 9 หลายเดือนก่อน +1

    Hi, thanks for what u've done so far. Yours is probably top youtube channel out there.
    I have some questions if u don't mind:
    - Take example you are using docker-compose to serve traffic & app. What if u need to horizontal scale. What kind of infra u'll choose in this case? K8s or sth?, or maybe docker-swarm I guess?
    - What is different between nginx and caddle u r using, what is the pros/cons of it

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      Idk I plan to just scale up vertically as much as possible and see how far it’ll take me. Caddy seems simplier, nginx is probably feature rich

  • @mhmt4603
    @mhmt4603 8 หลายเดือนก่อน

    As bad as it may sound now, I think it's good that you got ddos'd. That's how you and we learn. Thank you for your amazing content. And too bad for the 700$.

  • @ShootingUtah
    @ShootingUtah 8 หลายเดือนก่อน +5

    Maybe I'm just too new to the web dev world but this seems entirely convoluted! Just to stop a DDOS you have to apparently run and use like 8 build tools and different services and providers?!? What the hell has the Internet become?

  • @SeibertSwirl
    @SeibertSwirl 9 หลายเดือนก่อน +10

    Love ya! ❤ you’re doing a great job

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +4

      thanks sexy!

  • @teamvashmmo3218
    @teamvashmmo3218 9 หลายเดือนก่อน +1

    Great vid!! I wonder if this would help too: SST is moving to Ion apparently next week and making it so you can setup cloudflare as well as AWS resources, so you can mix and match cloud providers in your infrastructure as code. Would love to see you do the move to Ion and deploy your next.js site to cloudflare

  • @ismailzahhar
    @ismailzahhar 9 หลายเดือนก่อน

    GREAT technical video, looking to see more content in your channel on Deployment solutions and options. Great work man

  • @HeRvAsH93
    @HeRvAsH93 3 หลายเดือนก่อน +1

    Is if feasible to set up cloudflare ddos protection in front of an aws app to combine the serverless benefits with the protection?

  • @brunocascio
    @brunocascio 8 หลายเดือนก่อน +1

    You can configure a cloudflare tunnel which runs on your droplet, and avoid configuring ssl in both places but also you can avoid exposing your droplet

    • @WebDevCody
      @WebDevCody  8 หลายเดือนก่อน +1

      I’ll check that out, sounds easier

  • @siya.abc123
    @siya.abc123 9 หลายเดือนก่อน +9

    There we go!
    Lol I remember you yelling us to 'watch our dev ops privilege' or something like that when we called these cloud services out. You were junior and a cloud fanboy, I think this was last year 😂
    It's really interesting to watch you grow man

    • @SeibertSwirl
      @SeibertSwirl 9 หลายเดือนก่อน

      lol you’re probably part of the crew doing it huh?

    • @lukasberk9303
      @lukasberk9303 9 หลายเดือนก่อน

      Next video "Why should you should host simple projects on a VPS instead of AWS" ...............

    • @SeibertSwirl
      @SeibertSwirl 9 หลายเดือนก่อน

      @@lukasberk9303 at least you’re all learning together? 🥴 lol unless yall are just here to stare at his face for minutes on end which I guess is cool too 🫠

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +12

      all it took was a DDoS attack and an AWS linked to my credit card to change my thought process 🫠

    • @oSpam
      @oSpam 9 หลายเดือนก่อน

      @@WebDevCodyto be fair you could have (and still can) contact aws support. They would give credit to cover the full cost and help you protect in the future most likely. You also can get $1000-100000 based on being a startup, that could also help. It’s a shame you decided to fully make up your mind so soon.

  • @yoJuicy
    @yoJuicy 9 หลายเดือนก่อน +2

    Such good content. this could be a 5 hour paid tutorial with a next.js/VPS hosting stack. sst, docker compose, caddy, TLS, cloudflare etc.
    would love to know the performance loss with cloudflare in front.

  • @gadgetboyplaysmc
    @gadgetboyplaysmc 8 หลายเดือนก่อน

    THANKS CODY I LOVE YOU. I'm actually dogshit at Docker. Always have setup my garbage apps just manually. Always have just used Docker for spinning up DBs, not for containerizing the whole deployment. This was interesting. More Docker vids would be cool!

    • @gadgetboyplaysmc
      @gadgetboyplaysmc 8 หลายเดือนก่อน

      Can you also do a vid setting up coolify on a VPS next? Everyone's been going wild with it.

  • @SalvaToroTorus
    @SalvaToroTorus 9 หลายเดือนก่อน +2

    Nice to follow your journey. Thanks for sharing.

  • @hypnaudiostream3574
    @hypnaudiostream3574 2 หลายเดือนก่อน

    I watched your video about why you shouldn’t use a VPS from a year ago. I’m glad you came around 😂

  • @shanesreal
    @shanesreal 8 หลายเดือนก่อน +1

    You could also integrate cloudflare with aws loadbalancer, unless they attack you with cloudflare bypass; then maybe you still get charged.

  • @avinashjha7848
    @avinashjha7848 หลายเดือนก่อน

    Thankyou for giving us this precious information

  • @WittCode
    @WittCode 8 หลายเดือนก่อน +1

    I've always used a VPS for personal projects for this very reason! Companies I worked for all use AWS and the bills in dev environments alone put me off of using it...

  • @analogsensor
    @analogsensor 9 หลายเดือนก่อน +1

    Thanks for the video, that was very helpful, but I have a few questions, first is why are you using AWS for docker containers?
    Can I just put my container straight to the DigitalOcean?
    Second, is there some throwbacks for deploying nextjs to somewhere else instead of Vercel? And maybe there is some frameworks, that are more "deploy where you want" friendly? And I'm mostly talking about Nextjs as full-stack? Or do I need to split my backend and front end as different applications?
    P.S. I'm just starting to learn more about other frameworks and I'm considering switching from Nextjs (cause I'm stuck at Vercel)

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +1

      You can deploy next anywhere. It should have the same feature except edge computing. I was nit deploying containers on aws; I was using serverless

  • @armantgold
    @armantgold 5 หลายเดือนก่อน +1

    Coolify or dokploy seem viable alternatives to deploying on vps?

    • @WebDevCody
      @WebDevCody  5 หลายเดือนก่อน

      yeah both of those are good

  • @baetraki7268
    @baetraki7268 2 หลายเดือนก่อน

    You've came a long way from 9 month ago, was mad at you at the time but i see you have found the way my child.

  • @patolorde
    @patolorde 9 หลายเดือนก่อน +1

    Great video, i will try to replicate this setup. I dont want to go homeless

  • @mettle_x
    @mettle_x 9 หลายเดือนก่อน +1

    Nice walkthrough. If you still get into the same issue, perform those extra dance I posted in your last video. Good luck!

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      could you explain why AAAA would help out? if it's behind cloudflare, why would it make any difference?

    • @mettle_x
      @mettle_x 9 หลายเดือนก่อน

      @@WebDevCody Most of the internet still use IPv4 so most of the devices participating in a DDoS attack are presssmably using IPv4. If your VPS blocks IPv4 altogether, there will be one way to ping your server - that is through Cloudflare. Now someone can scan the ports of AWS to find the servers that have port 80/433 open and send an HTTP request to your server. However, if you don't use catch all block in Caddyfile: it sends something like 422 to deny requests. That's good but still it receives the HTTP request. Setting up IPv6 with AAAA record will future-proof your server as well. Also, users with IPv6 enjoy faster performance.

    • @mettle_x
      @mettle_x 9 หลายเดือนก่อน +1

      @@WebDevCody I wrote a long reply but it's not showing up here. Joining your Discord if we can have chat there.

  • @complikatd
    @complikatd 9 หลายเดือนก่อน

    Thanks for sharing these situations with the rest of us. Helps everyone!

  • @Kimitri
    @Kimitri 9 หลายเดือนก่อน

    I never search for cyber security so much like in the last night haha, I guess I learned your lesson too

  • @3ventic
    @3ventic 8 หลายเดือนก่อน

    You don't need to use Cloudflare's origin cert if you already have a valid cert. I also use Caddy and just let it do its default Let's Encrypt or ZeroSSL behind Cloudflare, reducing the amount of manual setup and configuration needed. The origin cert or another trusted cert is what you need for the "Full (strict)" option instead of just "Full".

    • @WebDevCody
      @WebDevCody  8 หลายเดือนก่อน

      Ahh ok good info!

  • @mountainash
    @mountainash 4 หลายเดือนก่อน

    A much easier way is to use Digital Ocean Apps pull your Docker Image from AWS ECR - it's web UI is very easy to setup, and the HTTPS certs are all automatically done for you (no need for Caddy and custom CF Origin TLS certs).

  • @fullstack_journey
    @fullstack_journey 9 หลายเดือนก่อน +1

    me looking at your bill: I'd be back to eating instant ramen for meals if that happens to me

  • @imam4521
    @imam4521 9 หลายเดือนก่อน +1

    I hope you make a detailed video on how to deploy next.js on VPS windows server .

  • @royalepros669
    @royalepros669 9 หลายเดือนก่อน +1

    Not sure if this is a stupid question, the bulk of the AWS bill comes from Cloudfront HTTP requests.
    Can you just change from using cloudfront as CDN to cloudflare? Instead of moving out of AWS completely?

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +1

      cloudfront has a bunch of path rules that know how to invoke lambdas on requests. It wouldn't be an easy refactor

  • @kamleshpaul414
    @kamleshpaul414 8 หลายเดือนก่อน

    can we use github repository to store docker image

  • @appel-32
    @appel-32 9 หลายเดือนก่อน +1

    yesterday we were talking in your discord about this issue, it's good you bring this type of content but at the same time is bad, there's a lot of people looking for "targets" and this type of videos bring a lot of attention.

  • @unclesam2941
    @unclesam2941 8 หลายเดือนก่อน

    DigitalOcean also has a container repository service, any particular reason to keep it on AWS ?

  • @gavinlindridge
    @gavinlindridge 9 หลายเดือนก่อน

    Really awesome to see how youve done it.
    Interested to know why you didnt go down the using of apps in digitalocean, you can literally just throw a docker container into it so you never need to ssh in etc.
    Though i definitely see some pros and cons to both approaches

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      Because I like wasting time 😂

  • @jitxhere
    @jitxhere 9 หลายเดือนก่อน

    Cody at 6:28 if you're using Cloudflare generated cert then you can safely turn on the full (strict) option in SSL

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      awesome, I'll turn that on

    • @EIsenah
      @EIsenah 9 หลายเดือนก่อน

      Are the certs free to generate? I'm currently using Let's Encrypt cert on my VPS and thinking of adding cloudflare for extra protection.

    • @jitxhere
      @jitxhere 8 หลายเดือนก่อน

      yes those are absolutely free and even you can select the term like 3months, 1years or even 15 years@@EIsenah

  • @afailable
    @afailable 8 หลายเดือนก่อน

    These videos are so helpful. Thanks so much man

  • @karanjeswani306
    @karanjeswani306 8 หลายเดือนก่อน

    Thank you for the great content as always. One question @WebDevCody. Deploying on vercel also doesn't save you from ddos?

    • @Miguelmigs24
      @Miguelmigs24 8 หลายเดือนก่อน

      They can be nice and forgive you the charge, but it will definitely break your free tier and scale your charges like crazy, a lot more expensive than AWS for sure

  • @anonymoussloth6687
    @anonymoussloth6687 9 หลายเดือนก่อน

    I am a bit new to tgese concepts. Can you explain why you shifted to a vps? Couldn't you have connected cloudflare to your cloud formation distribution?

  • @wavyboyjodii
    @wavyboyjodii 8 หลายเดือนก่อน

    "if not good luck" says a whole lot LOL. but thanks this is valuable.

  • @SickBeard
    @SickBeard 9 หลายเดือนก่อน

    6:06 CloudFlare can inspect all of your traffic in plain text.
    (This might be obvious, but I think it's always good to at least point out.)

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      right, I guess you have to trust cloudflare doesn't sell your data or forward it to the NSA 🤣

    • @RemotHuman
      @RemotHuman 9 หลายเดือนก่อน

      @@WebDevCody I feel like they definitely do forward it to the NSA. We need end to end encryption on our applications starting on the client

  • @DJohn001
    @DJohn001 8 หลายเดือนก่อน

    It would be fun if you could got a AWS engineer who helps you to secure you instances and let you make an interview about it to educate people who like us who are watching your channel. I mean it would also benefit them because your and other people with small side projects are more onto their products.

  • @reactdevops
    @reactdevops หลายเดือนก่อน

    Is bad solution to just use cheap vps with some proxy server like nginx and setup nginx for ddos protection?

  • @fionnbracken
    @fionnbracken 8 หลายเดือนก่อน

    Do you have to scp the certs to your vps everytime they expire or is there a way to automate that?

  • @jbzsfq
    @jbzsfq 8 หลายเดือนก่อน

    Could also host your own docker registry on the vps to store image?

    • @WebDevCody
      @WebDevCody  8 หลายเดือนก่อน

      I’ve never done that actually; but I’m sure it’s possible

  • @EliasJackson
    @EliasJackson 8 หลายเดือนก่อน

    Does cloudflare also have free DDoS protection for static websites and serverless functions that they host?

  • @reversetcp
    @reversetcp 9 หลายเดือนก่อน

    good to see people moving back to non-serverless stuff

  • @Lyric-w1r
    @Lyric-w1r 8 หลายเดือนก่อน

    when to use next js instead of react?

  • @Kumest183
    @Kumest183 9 หลายเดือนก่อน

    Hey, great videos! Learned a lot. I have a question: if you host it on the VPS, would you still get a higher bill if you get DDoSed without Cloudflare? Or do you only pay for the instance and it would just get laggy or go down?

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +1

      your instance would crash; therefore, there is no extra bandwidth you'd get charged for. It's just a trade off, would you rather have 100% uptime (you probably want serverless), or reduce your chance of getting a $600 in one hour.

  • @parlor3115
    @parlor3115 9 หลายเดือนก่อน

    I thought you said we should avoid hosting on raw servers as much as possible. What makes this project a plausible use case for VPS hosting?

  • @igortalic2021
    @igortalic2021 7 หลายเดือนก่อน

    Hey one question, why did you choose to move to digital ocean, was it an option to just add cloudflare in front of aws setup? Tnx, great video like always! 😊

    • @WebDevCody
      @WebDevCody  7 หลายเดือนก่อน +1

      Since this video I’m actually using railway now. Honestly I just wanted a service that has automatic billing limits which will kill my services if I spend too much money. Not many services provide this. Some have primitives I could use to build a kill switch from scratch, but I don’t have time to waste on that

    • @igortalic2021
      @igortalic2021 7 หลายเดือนก่อน

      Tnx for the answer, yeah I guess kill switch is a great feature! Didn't use railway will look into it 😊

  • @Kaviarasu_NS
    @Kaviarasu_NS 8 หลายเดือนก่อน

    While I have some hands on experience with dockerizing our apps, I’m new to other stuffs discussed. Can you please make a short video on how to have this set up from scratch to deployment ❤

  • @treksis
    @treksis 9 หลายเดือนก่อน

    Thank you for sharing rare experience to the public.

  • @ComfyCosi
    @ComfyCosi 9 หลายเดือนก่อน

    so does cloudflare not work with lambdas?

  • @franinja080
    @franinja080 9 หลายเดือนก่อน +1

    Extremely useful video, cheers

  • @omega_sine
    @omega_sine 9 หลายเดือนก่อน +1

    I always knew vps hosting was the right way 😎

  • @alvinolavarrieta
    @alvinolavarrieta 2 หลายเดือนก่อน

    the complexity 🤯

  • @zivtamary
    @zivtamary 8 หลายเดือนก่อน

    how do you handle ci/cd when you push to one of those repo's?

    • @WebDevCody
      @WebDevCody  8 หลายเดือนก่อน +1

      I’d probably build the image in GitHub actions, publish it to a container registry, then ssh into the machine and rerun docker compose up

  • @georgemwaniki
    @georgemwaniki 8 หลายเดือนก่อน

    Am a frontend developer and would love to transition to fullstack and master these deploment stuff, do you have a course on this or one you recommend ?

  • @NaourassDerouichi
    @NaourassDerouichi 9 หลายเดือนก่อน

    Can't wait for the attacker to ddos test the new setup :D

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +2

      if he does I'm quitting

    • @Lostlabs
      @Lostlabs 8 หลายเดือนก่อน

      @@WebDevCodyNo need to worry you are fine now unless you are charged for your AWS servers running in the backend per request you're fine. I would recommend not using AWS at all it's overpriced and trash IMO.

  • @emsp5558
    @emsp5558 9 หลายเดือนก่อน +8

    damn feel bad for u

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +13

      🤷‍♂️ you live and you learn

  • @Cyber_Lanka
    @Cyber_Lanka 9 หลายเดือนก่อน

    Nice. I remember commenting on last video asking why you didn't use CF. I mean you could use CF with EC2 if you want.

  • @codingbythemoon
    @codingbythemoon 8 หลายเดือนก่อน

    Sorry to hear about AWS bill. But did you not have cloudflare setup already in front of AWS? Because you mention WAF. Did it not work properly?

    • @teamvashmmo3218
      @teamvashmmo3218 8 หลายเดือนก่อน

      He had cloudfront, which is AWS's CDN

  • @CodeZakk
    @CodeZakk 8 หลายเดือนก่อน

    what people gain from making this type of attacks? also if you use vercel the price will be i think 10 times how do you protect if you use vercel. thanks in advance😊😊

  • @oneguyyyy
    @oneguyyyy 9 หลายเดือนก่อน

    Thanks for sharing this with us!

  • @SeanCassiere
    @SeanCassiere 9 หลายเดือนก่อน

    I don't remember the steps, but you can set your VPS to not accept connections that are not on the internal network and not from Cloudflare. Just remember to allow ssh over a custom port.

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +1

      I did that today, I setup a DO firewall rule and only allow inbound requests from cloudflare specific IP addresses.

  • @joeyywill1234
    @joeyywill1234 9 หลายเดือนก่อน

    Cheers for the insight my duuuude

  • @can_uysal
    @can_uysal 8 หลายเดือนก่อน

    Why don't you use cloudflare + aws (sst)? Is there a way for it? I really like sst and aws deployment and would like to use cloudflare in front.. What made you go vps instead of this setup (if exists)

    • @WebDevCody
      @WebDevCody  8 หลายเดือนก่อน

      Honestly, I’m kind of just tired of serverless and lambda at work we use lambda and I can’t even count how many hours I’ve wasted trying to get binaries to run on lambda ran into lambda size limits, run into API Gateway timeout issues run into having debug permissions over and over again Execution roles having to deal with cold starts that make the application. Just feel slow when you don’t already have a ton of users. Honestly, I think just hosting a single node executable on a VPS or a container runner is extremely low maintenance compared to anything you can hack together in the AWS ecosystem.

  • @rawallon
    @rawallon 9 หลายเดือนก่อน +1

    That's cool, but it doesn't have ci/cd, correct?

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      Correct, not yet. It’s not hard to ssh into a machine and run a single command to deploy new versions

    • @PASTRAMIKick
      @PASTRAMIKick 9 หลายเดือนก่อน

      digitalocean does seem to have CLI tools, with that and some other stuff like Ansible you might be able to get a CI/CD going.

    • @RedVelocityTV
      @RedVelocityTV 9 หลายเดือนก่อน

      Might be overkill but I'm using Gitlab with docker in the same server to build and deploy docker projects.

  • @bhavyajain638
    @bhavyajain638 9 หลายเดือนก่อน

    Why did you use a custom TLS cert with caddy when configured caddy to do it automatically?

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +1

      You have to use the cloudflare cert or else you have to do a bunch of extra work

  • @tobiiias1793
    @tobiiias1793 8 หลายเดือนก่อน +1

    next: setup traefik on the VPS instead of caddy (Labels in composefile set up the config for Reverse Proxy)

  • @TecsoSolutions
    @TecsoSolutions 9 หลายเดือนก่อน

    Weren't you using Amazon Shield Standard with Cloudfront? It appears to be free and protect against DDOS.

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      yeah, but it obviously isn't blocking all the DDOS traffic

  • @thehibbi
    @thehibbi 9 หลายเดือนก่อน

    I feel bad for you that somebody out there is eager enough to DDOS you. But this video was very helpful, thanks!

  • @leguizbsit3162
    @leguizbsit3162 9 หลายเดือนก่อน

    How can you know that thing. How can you understand that what should i need to know so i can get it. Read the docs?

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      I have no clue what you just asked

    • @leguizbsit3162
      @leguizbsit3162 9 หลายเดือนก่อน

      @@WebDevCody I'm just amaze how can you learned that. Like choosing where to host and use other tech to secure your application

  • @emmanuelU17
    @emmanuelU17 9 หลายเดือนก่อน

    Out of curiosity, can’t you achieve the same thing with aws api gateway and EC2?

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +1

      Same thing, meaning ddos protection or hosting your api?

    • @emmanuelU17
      @emmanuelU17 9 หลายเดือนก่อน

      @@WebDevCody Actually I just thought about it, api gateway, EC2 wouldn’t work against ddos protection but will work with API hosting.

  • @internetexplorer7880
    @internetexplorer7880 9 หลายเดือนก่อน

    Ah that would definitely hurt my wallet too. I was planning to use vercel and use cloudflare over it. Any chance you can make a tutorial for this?

  • @cloudeater9571
    @cloudeater9571 8 หลายเดือนก่อน

    Doesn’t DO offer DDOS protection, or is that not available for their droplets/whatever you used for the VPS? Naturally any and all protection sounds good lol

  • @shirkit
    @shirkit 8 หลายเดือนก่อน

    Honestly, for side projects, you can have the 2 CPU 2 GB of RAM and never worry again about DOS, just put a firewall on the OS. Now DDoS is a different story, and i honestly don't think the attacker will continue for much longer. Just services will be offline for a little while, but since they are side projects shouldn't matter much. I can hardly phantom how you have Node and potentially other things running with 1 GB of RAM and not run out of memory.

    • @WebDevCody
      @WebDevCody  8 หลายเดือนก่อน

      node can easily run without needing 1gb of memory; it isn't java, give node some credit

  • @tljstewart
    @tljstewart 8 หลายเดือนก่อน

    nice stuff, why not use aws vps with cloudflare?

    • @WebDevCody
      @WebDevCody  8 หลายเดือนก่อน

      Because if I want a vps, DO or railway has a much better ui for cheapee

  • @blackblather
    @blackblather 8 หลายเดือนก่อน

    Dude, in an interview for a SWE the guy asked me if i'd use aws in my starup that im running. I said no cuz its too expensive. He looked at me like im crazy.
    Then he asked me if i had a lot of users would i switch to aws?
    I said it depends: users dont mean customers. A lot of users means a lot of requests means a lot of cost.
    As a founder you have to manage your finances and these interviewers dismissed me for saying what i said.
    I did work with aws in the past, but the organization was huge with many millions in revenue, not a startup 😅

  • @Jack-kf1tn
    @Jack-kf1tn 9 หลายเดือนก่อน

    does it not make sense to just use cloudflare with your aws project. Or is it necessary to use a vps to prevent the DOS attack?

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน

      I'm sure it's possible, but I'm a bit tired of serverless

  • @flexdash
    @flexdash 9 หลายเดือนก่อน +1

    Digitalocean + Caprover

  • @claudeb.3473
    @claudeb.3473 9 หลายเดือนก่อน

    Just curious, why didn’t you deploy this NextJS app on Vercel’s free tier?

    • @JustPlayerDE
      @JustPlayerDE 9 หลายเดือนก่อน

      that is the same issue as AWS, just at least 5 times more expensive (free tier is a auto-upgrade if you hit the limits, you still owe money even if no card is linked)

    • @WebDevCody
      @WebDevCody  9 หลายเดือนก่อน +2

      Vercel free tier license states it can’t be used for commercial apps; my app getting ddos is making money