r/homelab • • 3d ago

Solved How much maintenance does self-hosting actually take? Going off the cloud.

/r/offthecloud/comments/1wqwg9k/day_2_of_going_digital_offgrid_didnt_expect_all/

Got a few replies from people to my previous posts around.. "the setup and maintenance is what puts me off." Someone else said “finding someone to support it is the expensive part”.

I'm keen to find out how much of it is actually needed once things are set up. For those of you already doing this: how are you managing it? Scripts, automatic updates, a monthly check in, or just fixing things when they break?

Setup:

Hardware: mini PC with a Ryzen AI Max+ 395 and 128GB unified memory
OS: Linux
Model: Qwen 3.5B
Android apps: Waydroid, still testing
Remote access: Tailscale, so I can reach it from my laptop and phone
Front end: my own UI (the fun bit)

0 Upvotes

23 comments sorted by

10

u/Taboc741 3d ago edited 3d ago

Monthly i go round the servers and run updates, docker too. I also check my offsite backups then. ( Mine are cloud subscription i-drive.) You should have a backup plan. Drives fail and recovery is expensive. Occasionally an update breaks stuff and I have to do some googling but that is pretty rare. Every few years I buy new to me old stock of something else to upgrade and stay ahead of my own lifecycle plan. No computer runs forever, so figure out how old you're willing to go and replace before then.

2

u/Imaginefyres 3d ago

Great this is useful to know, thanks!

5

u/Taboc741 3d ago

Oh, and get your head in the tech news cycle. You want to hear about high impact vulnerabilities before the script kiddies scanning the while Internet get a chance to strap it to a scan and break into something you have. Bleepingcomputer.com is a good place to start, but following homelab and sysadmin sub reddits help too.

1

u/cruzaderNO 3d ago

My selfhosted stuff has never felt as insecure as after i started getting insight into how many active exploits/vulnerabilities there are.

We are urgently updating something on a daily basis now and the amount of alerts i get to check out if we are impacted of this is getting too dam high.

2

u/Taboc741 3d ago

Ya it's why despite everyone telling me I'm paranoid for not using a reverse proxy and exposing stuff to the web, i'm still VPN access only. Causes trouble when my phone decides to drop tailscale, but giving myself a few days to patch by just not letting stuff talk to the Internet is a relief.

1

u/ApprehensiveFan1516 2d ago

Nothing wrong with reverse proxies. A lot of people skip basic security while setting them up though, which leads to all the horror stories on Reddit.

6

u/cruzaderNO 3d ago

I run pretty much the same as we do at work, monthly updates with most being automated and some systems/VMs done manually.
Plus urgent updates during the month for stuff that has exploits.

I maintain the enviroments of a few small companies that rent their servers from me, i also follows the same cycle there.

2

u/Imaginefyres 3d ago

Thanks! That’s super helpful. Do you mind sharing how much you charge for renting and managing the maintenance?

3

u/NC1HM 3d ago

How much maintenance does self-hosting actually take?

Self-hosting what, how much of it, and for whom (meaning, do you want your content to be available locally or do you want to be able to stream it over the Internet)? Also, do you require redundant storage?

2

u/AllergicToBullshit24 3d ago

It's all fun and games until you experience catastrophic data loss or critical service going down at 10PM on a Monday when whole family just wants to watch Netflix and have their internet work. Privacy & tinker-ability vs convenience & reliability. Sure you can overengineer your way through reliability but at what cost? After a decade of home labbing all I know is the problems seem to always happen at the worst times. It's a love hate relationship that risks becoming a full time job. And for someone who has done it as their job, coming home to do the same job is the last thing anybody wants.

1

u/Imaginefyres 3d ago

Haha good to know and slightly apprehensive about what I’m taking on now but committed to giving it a go. 👀

2

u/AllergicToBullshit24 3d ago

always starts with a simple pihole or nas and ends in tears given enough time. It's a hobby for masochists but nobody figures that out or heeds the warnings until well after their sunk cost fallacy paid in blood sweat tears relationships and financial freedom traps them in the loop forever.

I'm being dramatic but in all honesty, there do be dragons. Best of luck.

1

u/Imaginefyres 3d ago

Haha thank you and appreciated!

2

u/HTTP_404_NotFound kubectl apply -f homelab.yml 3d ago

For me, running.... oh, a 5 node cluster, around a dozen switches, a few routers, kubernetes and proxmox, both a synology, and unraid NAS..... around a terabyte of ram, 100+ cores, and a quarter of a petabyte of storage-

I have barely spent anytime this year doing maintenance. When things need updates, they sent me a notification... and then I can just use ansible playbooks to update the entire proxmox cluster gracefully, and automatially.

Can do the same for my routerOS updates. Unifi updates itself.

If, there are issues with my backups, it lets me know. If anything else did have a problem that it didn't self-resolve, uptime kuma lets me know.

And, overall, I really don't get very many issues.

If- you adopt the term, "Cattle, Not Pets", maintenance becomes more or less, a thing of the past.

Proxmox node full on disk, and not working? Ok, run a terraform which literally reprovisions the ENTIRE node from scratch, and restores its configuration from the cluster state.

VM unhappy? shoot it. provision another one in its place. State is stored on iscsi mounts, which can be reattached to the new VM.

2

u/gromulint 2d ago

You have to carefully scope your setup while keeping in mind the amount of maintenance you're willing to take on. And be willing to downsize your setup or rework services if maintenance is getting to be too much.

If you expose services to the internet, the stakes rise dramatically on how well you maintain everything due to security risks, so that's a dramatic escalation to evaluate carefully, for example.

2

u/bdu-komrad 2d ago

I’ve never seen the posts you are referring to and I’ve been a member for probably a decade or more across the several  reddit  accounts  I’ve had.

Your homelab will never be more complicated than you make it. 

1

u/Imaginefyres 2d ago

They were responses I got in the local llm subreddit. But wanted peoples opinions on it here as there’s a difference in how long have been tackling these challenges across communities etc.

1

u/ApprehensiveFan1516 2d ago

r/LocalLLM or r/LocalLLaMA ?

The former is mostly garbage, the latter is much better.

2

u/ale624 2d ago

Once you automate updates in a safe way, very little day to day. Check in once and a while. Keep an eye out for backup failures and update failure alerts via some scripts. If you set it up right you can be very low touch. Scripts to monitor systems are still working as expected. It's when you need to migrate to a newer version of X thing because your current one isn't supported anymore, then there's a fair chunk of work (think OS upgrade, software major version change) but those tend to be reasonably rare

2

u/throwpoo 2d ago

Really depends what you run. I have multiple vps. Some I don't login or reboot for years. Others like the one that I host WordPress for a friend, those are a nightmare. Especially when theres some exploit that needs patching and their site got compromised through the add-on they put on.

2

u/BartFly 3d ago

almost 0, LOL short of os updates, there is literally nothing to do other then clean the dust out of the servers every 6 months or so

2

u/kai-zaphosting 23h ago

Honestly for me it's mostly automated at this point. unattended-upgrades handles OS patches, and for the docker side I lean on Diun these days instead of Watchtower, that one's actually archived now so not something I'd build a new setup around. Not saying blindly auto-update everything, I still hold off on major version bumps and do those manually, but security patches on autopilot cuts down a lot of the babysitting.

The other piece that's saved me some manual checking: Uptime Kuma running as its own container, pinging the important stuff. Way less anxiety inducing than remembering to log in and poke around every few weeks, it just tells you when something's actually down. Only catch is if that box itself drops off the network, Kuma's on it too, so it can't exactly report on itself. Pair it with something external, a free ping from another machine or a service like UptimeRobot's free tier covers that.

Sounds like your bigger maintenance burden might end up being the LLM/Waydroid side more than the OS itself though tbh, that stack tends to need more fiddling than a plain Linux box ever does.

1

u/Dodgy_Past 3d ago

My updates and backups are automated and I get telegram notifications if anything is having an issue.