DevShelf

Production-grade self-hosting resources for developers, homelab operators, and privacy-minded builders. Guides, configs, and scripts — no fl...
Málaga, ES
Created byProfile pictureOrlando
3 joined
Profile picture
OrlandoProfile picture@deploy1t·Jun 26
Pinned post

Why most self-hosted setups fail (and how to fix yours)

Most self-hosted setups don't fail because of bad hardware or wrong distro choices. They fail because they were built to work once — not to survive an update, a crash, or a 3am reboot.


Here's what separates resilient stacks from fragile ones:


1. Reproducible configs, not tribal knowledge


If your setup only exists in your memory and a pile of ad-hoc apt install commands, it's already broken. Write your entire stack as code — Docker Compose files, Ansible playbooks, or at minimum a setup script. If you can't rebuild from scratch in 30 minutes, you don't have a stack, you have a snowflake.


2. Reverse proxy is not optional


Exposing services directly on raw ports is how you end up getting scanned, exploited, and spending a weekend rebuilding. Traefik or Caddy in front of everything — TLS termination, subdomain routing, auth middleware. Non-negotiable.


3. Backups that you've actually tested


A backup you haven't restored from is not a backup. Schedule automated snapshots, ship them offsite (S3-compatible works great), and run a restore drill at least once a quarter. Restic + rclone is a solid combo.


4. Hardening before you open ports


Every VPS is getting scanned within minutes of launch. Fail2ban, UFW, SSH key-only auth, and disabling root login are your baseline — not afterthoughts.


Drop your current stack setup in the comments. Let's see what people are running.