Skip to content

Cloud Services

The paid infrastructure, kept separate from the home server because the failure modes are different. On the home server I control the box, the network, and the DNS. Here I'm trusting someone else's control plane and paying monthly for the privilege.

Three providers live here:

  • Cloudflare — DNS, the edge, Zero Trust access, Workers, and Pages. The free tier covers everything I need.
  • AWS — Lightsail, S3 static hosting, RDS, and SES. Mostly historical now: my current hosting is a home VPS behind Pangolin, but I still register domains through Route 53 and send transactional email through SES, so the setups stay documented.
  • Microsoft 365 — email. Not a server, just the provider I run business mail through. The part that actually matters is getting DKIM, DMARC, and SPF right so outgoing mail doesn't land in spam.

What I run today

Provider What it's for Notes
Cloudflare DNS for every domain, Pages for frontends, mTLS and Access on the sensitive apps, CrowdSec worker bouncer Free tier
AWS Route 53 Domain registration Domains delegate nameservers to Cloudflare
AWS SES Transactional email from the apps Sandbox until limits are lifted
Microsoft 365 Business mailbox, aliases across multiple domains DKIM has to be enabled by hand
Pangolin VPS Public ingress for self-hosted apps Documented under Self Hosted

The home server half is not here. This section is only the cloud half — the parts where a third party is between me and the traffic.

Comments