How do I migrate my VPS out of Cloudflare?
from enchantedgoldapple@sopuli.xyz to selfhosted@lemmy.world on 30 Dec 11:42
https://sopuli.xyz/post/38864934

I have Pangolin set up as a reverse proxy in my VPS and Cloudflare as a DNS provider with its free tier.

I want to migrate out of Cloudflare for my setup, however I lack the requisite network knowledge to safely transition my VPS and domain to better alternatives and don’t know where to start its research from.

There are two features I intend my setup to have after the transition:

Again, I don’t have much knowledge in this field but I’m willing to learn and make an informed decision. Please let me know any suitable alternatives for the above, the pros and cons for the migrations, or some guide on performing such transition from Cloudflare as you seem fit.

#selfhosted

threaded - newest

stratself@lemdro.id on 30 Dec 11:57 next collapse

For the DNS provider I recommend desec.io. It’s a nonprofit running worldwide DNS servers, supports DNSSEC, and has a plugin for Lego. If your registrar supports DNSSEC as well, I’d recommend enabling it to protect from DNS forgery.

For the DDoS protection I don’t have a recommendation as they’re all “just another SaaS”, but maybe you could limit many more selfhosted things behind auth as to not expose more surface to potential scrapers.

CameronDev@programming.dev on 30 Dec 13:13 next collapse

Crowdsec does not provide DDOS protection in the same manner as Cloudflare. You can use crowdsec to block the traffic at your server, but it has already reached your server, and will be using up your ingress bandwidth regardless. So if you were DDOS’d, your site will go down.

Cloudflare prevents the traffic ever reaching your server, while allowing the legitimate traffic through. They block it on their servers, which have much higher bandwidth than any VPS provider has.

non_burglar@lemmy.world on 30 Dec 15:27 next collapse

There is no competition for ddos protection unless you enter into an arrangement with akamai or fastly, which won’t happen unless you have the traffic and the $$$ to support it.

Cloudflare can soak up volumetric traffic at scale. Crowdsec cannot do this, because the “crowd” par of crowdsec is rulesets, you are still doing all the heavy lifting with your own infra.

irmadlad@lemmy.world on 30 Dec 16:41 next collapse

Google Cloud Armor, AWS Shield, Fastly, Akamai, Incapsula, Freenom World, DDoS-GUARD, Netlify, all offer some level of DDoS and plans vary widely. Cloudflare’s Tunnels/Zero Trust free tier is quite generous. I realize some selfhosters have an aversion to Cloudflare, but Cloudflare is very good at what they do. There are VPS hosts that do offer DDoS protection like DigitalOcean, Vultr, Linode, A2 Hosting, Hostinger, OVH, however, it’s usually just basic DDoS protection. Maybe check with your host to see what they offer.

Most edge DDoS protection of any merit is going to be the big guys. You could lock down your VPS to only you and your handful of friends, but unfortunately, in the event of a DDoS attack, your server will be bearing the brunt of the attack. Is your VPS server of a nature that would elicit repeated DDoS attacks? I’ll have to say, anecdotally, that I’ve never experienced one, but that is no guarantee that you wouldn’t either.

jpaskaruk@growers.social on 30 Dec 19:22 collapse

@irmadlad I have a couple of sites going through Cloudflare Zero Trust, strictly done to get my head around Cloudflare, but at this point I'm kinda settling into just using Wireguard for everything personal, and I'm gonna push my Fedi servers through Cloudflare, because they are all public-facing information; if someone has a secret lost on the fedi, it's not because of Cloudflare, it's because they posted a secret on a 100% public network.

@enchantedgoldapple

irmadlad@lemmy.world on 30 Dec 19:40 collapse

I’m kinda settling into just using Wireguard for everything personal

Wireguard is very capable. In that vein, Tailscale is pretty straight forward.

growers.social: Welcome to Growers Social, the perfect online community for green thumb enthusiasts!

Checked it out. Looks pretty cool. I do dabble…I’ll check it out in depth at a later date.

jpaskaruk@growers.social on 30 Dec 20:01 collapse

@irmadlad I don't run this instance, but I do generate so much of the traffic, I'm told, that I might as well 🤣

I already registered chezpants.ca nearly a year ago and I run my own servers, I've been stuck in decision paralysis about regular Mastodon vs GoToSocial. I think I've decided, just need a day to get it up and relearn CloudFlare...

irmadlad@lemmy.world on 31 Dec 19:38 collapse

just need a day to get it up and relearn CloudFlare…

Well, if you get stuck, I have a set of instructions for Cloudflare Tunnels/Zero Trust I’d be happy to share. They’ve seemed to have helped a few people, so lmk.

EarMaster@lemmy.world on 30 Dec 20:26 collapse

Do you really need that DDoS protection? I have been having my own webserver for decades now hosting public sites and I have only once been in the position that my server was not reachable because of a DDoS attack. And even then the attack was not targeted at my server but at my hosting provider at that time. Everything else was handled by fail2ban easily…