Cloud Services¶
The paid infrastructure, kept separate from the home server because the failure modes are different. On the home server I control the box, the network, and the DNS. Here I'm trusting someone else's control plane and paying monthly for the privilege.
Three providers live here:
- Cloudflare — DNS, the edge, Zero Trust access, Workers, and Pages. The free tier covers everything I need.
- AWS — Lightsail, S3 static hosting, RDS, and SES. Mostly historical now: my current hosting is a home VPS behind Pangolin, but I still register domains through Route 53 and send transactional email through SES, so the setups stay documented.
- Microsoft 365 — email. Not a server, just the provider I run business mail through. The part that actually matters is getting DKIM, DMARC, and SPF right so outgoing mail doesn't land in spam.
What I run today¶
| Provider | What it's for | Notes |
|---|---|---|
| Cloudflare | DNS for every domain, Pages for frontends, mTLS and Access on the sensitive apps, CrowdSec worker bouncer | Free tier |
| AWS Route 53 | Domain registration | Domains delegate nameservers to Cloudflare |
| AWS SES | Transactional email from the apps | Sandbox until limits are lifted |
| Microsoft 365 | Business mailbox, aliases across multiple domains | DKIM has to be enabled by hand |
| Pangolin VPS | Public ingress for self-hosted apps | Documented under Self Hosted |
The home server half is not here. This section is only the cloud half — the parts where a third party is between me and the traffic.