Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

83% Positive

Analyzed from 1083 words in the discussion.

Trending Topics

#openbsd#though#bsd#running#free#sshd#com#https#man#vultr

Discussion (33 Comments)Read Original on HackerNews

dchestabout 2 hours ago
A warning about openbsdhandbook[.]com - this website has completely incorrect information for some things. Like hallucinated, even though I think it was created before LLMs.
tolerance42 minutes ago
While we are recommending and un-recommending resources https://romanzolotarev.com/bsd/ has been my go-to.

joshua stein's interest in getting OpenBSD running on anything he can provides useful insight too https://jcs.org/tagged/openbsd

imwally31 minutes ago
Dang, I didn't know that. I thought it was decent enough to get people exposed to doas(1), pkg_add(1), syspatch(8), etc... from which they could then read the man pages.

Thanks for pointing this out and I appreciate the other recommendations in this thread. Massive +1 for @jcs. That dude is awesome and puts out great stuff.

SoftTalkerabout 1 hour ago
For BSD (especially OpenBSD) you can pretty much just use the man pages and the online FAQ. They are really good.

If you want a book, Absolute OpenBSD is good though a bit out of date now. A lot of it would still be applicable though, if backed up by the current man pages.

Reading undeadly.org is a another good way to keep up on developments.

8by3about 4 hours ago
I've always gone with Vultr (vultr.com) for BSD VMs, its properly supported by them and while I've never hard verified this, they seem like a nice smaller player. Like they have offered Open/Free BSD VM's for > 10 years, kind of nice.
QuantumNomad_about 1 hour ago
I have a couple of FreeBSD VMs on Vultr. For quite some time sshd regularly dies on one of them and I am not sure why.

A couple of theories I’ve had is that maybe

a) my VM was compromised and there is a persistent rootkit installed that kills sshd, or

b) file corruption after previous unclean shutdown has left some file needed by sshd corrupted and it leads to this behaviour, or

c) maybe it’s running out of memory sometimes

Each time I want to ssh into the machine I usually have to first connect with the VNC from the vultr dashboard to start sshd up again.

It’s running the latest FreeBSD, as every now and then I log in and do an upgrade on it some time after a new version has been released.

A persistent rootkit may have been installed if it was compromised between when some vulnerability became known and when I later upgraded next time.

If a file was corrupted in an unclean shutdown in the past maybe it’s a file that has not been changed between FreeBSD versions so even though upgrades replace some files maybe it’s the same corrupted file all along.

Ideally I’d just reinstall the machine, but that’s always more of a hassle than it should be so I continue running the VM in this broken state where sshd keeps dying every now and then.

cyberpunk42 minutes ago
Well, you can at least run "freebsd-update IDS" on this system to verify the base system, "pkg check -s -a" would check the integrity of files installed via pkg also.

It will only take a few min..

QuantumNomad_26 minutes ago
Neat! Haven’t tried either of those before.

While I’m at it I also took a quick look now at output of `top` and it’s sitting at 27 MB free RAM lol. So from that, out of memory is very likely the reason I keep having sshd die on me.

SoftTalkerabout 3 hours ago
I used buyvm.net for BSD a while back. Didn't have any issues, and the few times I contacted their support they were quick to respond and helpful.

rootbsd.net before that, but they don't seem to exist anymore.

SpecialistKabout 2 hours ago
They were very helpful when one of the AMD firmware patches in 7.3 caused my VPS to not boot. They even offered to apply a manual fix until patch -015 was available which fixed it.
darksim905about 2 hours ago
The admins have access to your data and unless things have changed, that isn't monitored. They also bend to NSLs like any other provider. What they charge vs what things cost hurts.
thesuitonymabout 2 hours ago
Any cloud compute vendor will have access to your data unless you encrypt it.
cyanmagentaabout 1 hour ago
> unless you encrypt it

And to clarify, this means encrypt it before it gets to the VPS. Just having full-disk encryption is not enough because cloud providers can dump RAM. There are tools that easily extract encryption keys from RAM.

So, really, you need to trust the cloud provider unless everything is encrypted on computers you own.

FLeXMurphyabout 2 hours ago
DO burned me recently due to their unwillingness to handle DDOS attacks: "The best we can do is change your IP." Thanks guys.

Switched to OVH immediately.

thatjoeoverthrabout 1 hour ago
I migrated a client off for the same reason. The “app platform” ran behind Cloudflare, but they run the Cloudflare, so I couldn’t put it behind my own Cloudflare, nor could I configure it and solve the problem. Moved the entire thing to Hetzner, fast. What a week.
forintiabout 2 hours ago
I tried to warn them that they were hosting a phishing site once and they weren't very receptive.

Otherwise, I hosted a site with them for years and all went well.

crestabout 2 hours ago
They're also too stupid to understand that they've been dropping UDP datagrams with src port == dst port and < 1024. This obviously breaks IPsec IKE. I showed them dummy traffic captured with netcat and tcpdump, but they refused to admit they caused the problem. They repeatedly claimed to see nothing dropped between the pcap files, that I was doing it to myself with a firewall that wasn't even enabled, or that this is just how a network is supposed to work.
githubholobeatabout 3 hours ago
You can even go completely free with Cloudflare tunnel with your own office/home hardware. I have a simple web running on my old Raspberry Pi 3 + nginx + golang web app. Also with ssh access to the Pi.
hughw40 minutes ago
You don't even need your own hardware. You can serve your site using the free CF Workers plan. Of course, that's a different goal than running bsd in an aggressively tiny cloud instance.
xp84about 2 hours ago
Yes, the cloudflare SSH tunneling works well -- though I think the fact that SSL is provisioned means it'll show up in the cert transparency log, possibly attracting unwanted attention to probe my home systems.

I ended up turning that off and switching to Tailscale. Tailscale is set to advertise my home IP range (I chose one that's not 192.168 based which avoids problems with range conflicts). So I can just connect to Tailscale and connect to 10.X.Y.Z as though I'm home. If I want memorable hostnames I can point DNS records to those private IPs.

altmanaltmanabout 2 hours ago
You still have to pay for electricity. If you consider that "completely free" then paying $4 per month should also be considered "completely free".
cedricgleabout 3 hours ago
Does DigitalOcean still only propose up to 4 basic cpu as droplet maximum ?. All their compute capacities disappeared overnight 2025/2026 without any reason.
andaiabout 3 hours ago
I heard all the RAM scheduled to be manufactured next year had already been sold out. Maybe that's a related phenomenon?

https://news.ycombinator.com/item?id=49207236

e.g. Hetzner tripled prices recently.

https://news.ycombinator.com/item?id=48542064

toleranceabout 2 hours ago
Back in my day a blog post like this would've included a promotional link for $100 in DigitalOcean credits!
daneel_wabout 3 hours ago
I run OpenBSD at netcup.de for €2/month. It's very low-spec, but it's enough.
slekkerabout 4 hours ago
For a little bit more you can rent on https://openbsd.amsterdam - they also donate to the OpenBSD foundation!
leonheldabout 3 hours ago
Man I always look at this project with nothing by awe. I'd love to start something like this... if you're in central Switzerland and would like to copy their model, hit me up.
8by3about 3 hours ago
They are cool, man they've grown. I used that when there were ~20 VM's on there. Its a great project but think its only physically in Amsterdam which is why I ended up moving back to vultr, as they have many more options.
doublepg23about 2 hours ago
+1 for obsd.ams , great VPS!
assimpleaspossiabout 2 hours ago
RamNode does $2/month but just one ipv6 address. Add a ipv4 address and it's $4/month.
Scarbuttabout 3 hours ago
Crazy that after so many years of cloud compute a 8GB VM is $48/mo.
toast0about 2 hours ago
If you can, it really makes sense to look for low cost dedicated servers. For $35/month I get a whole machine with dual L5520 and 24 GB of ram. I used to have a little nicer server for a little less, but that provider had to close because their costs for electricity and space went up too fast. Yes, the L5520 is ancient, but my server needs are tiny and it's fun to have a whole machine.

Look on webhostingtalk or lowendbox or lowendtalk.