The idea came up because I deployed a bunch of applications at home, and my home broadband has a dynamic public IP address, so sometimes when friends need to access them, I can only usehttp://动态域名:端口to temporarily send it to others. Originally, the HTTP method is in plaintext, and it is not a standard port 80, so mobile browsers or the built-in browser in WeChat will prompt that it is insecure, which looks very low-class.
So I thought I might as well take this opportunity to organize the applications at home (preferably unifying the deployment methods too), and then publish them externally using HTTPS through a unified reverse proxy. But the internet is insecure, and since applications are being officially published externally, shouldn't security be a must-consider? Then I thought, if security is considered, shouldn't O&M (operations and maintenance) also keep up? ... In the end, I thought since I've considered so much, I might as well make building a home data center the ultimate goal.
P.S. Another advantage of a home data center is that you can trade residential electricity bills for performance: the performance of general low-end cloud servers (1-core, 2-core CPU; 1G, 2G RAM) is pretty mediocre and may not match the performance of your own home devices (or even fall far short). For example, my current two main devices: a base-model M1 Mac mini and an Intel 13th-gen CPU + 64G RAM mini PC costing over 3,000 RMB. If converted to a cloud server of equivalent performance, how much would it cost per month?? It's simply unimaginable, whereas now it only costs dozens of yuan in electricity bills per month to own. Isn't that great?
As for the stability issue... nowadays, the failure rates of Alibaba Cloud and Tencent Cloud aren't low either.
Of course, the biggest fear for a home data center is a power outage, and there's nothing I can do about that. I solved this problem by building a disaster recovery site on a cloud server (the cheapest one will do, mainly for ICP filing). Normally, a detection script runs periodically (every few minutes) on the cloud server to probe the availability of the main WordPress site at home. Once the main site is found to be interrupted (whether due to a power outage or network disconnection), the disaster recovery site automatically becomes the main site and starts providing services.
Note: To achieve the above functions, a series of underlying key technologies are required for support.
As mentioned earlier, to have a good experience (and look high-class) when accessing applications in the home data center, you need to solve the problem of adding ports after the domain name. Consequently, you must use ports 80 and 443. However, to use ports 80 and 443, relying solely on the public IP of the home broadband itself is not enough; other methods must be used, which fall into two major categories.
Without domain ICP filing, use Cloudflare (regardless of whether the home broadband has a public IP address or not)
This method is actually leveraging the services provided by Cloudflare's free plan for free. This is my recommended method, and it has many advantages:
a. No ICP filing required
b. Multiple origin-pull methods to choose from, regardless of whether the home broadband has a public IP address (but try not to use public IP origin-pull, as domestic ISPs are currently very strict about inspecting access to non-ICP-filed domains)
c. Cloudflare provides a one-stop service through its edge network: website building, CDN, basic DDoS protection, and WAF. So basically, for general personal webmasters, it can be a one-stop solution where you don't have to worry about anything (of course, the premise is that you know how to configure it reasonably yourself, as these functions are turned off by default, and these are only the most basic ones).
Of course, this method also has many disadvantages, and they are relatively significant:
a. Without VPN or proxy tools, you might not even be able to access the Cloudflare official website (some regions can access it directly, but it mostly depends on luck)
b. Properly configuring Cloudflare's many features requires a certain technical foundation, and learning it comes with a significant time cost
c. It is not difficult to set it up directly so that it is accessible, but optimizing it for faster access within China requires a lot of tweaking
Although the barrier to entry is high, I still recommend this method. Even though it requires learning and tinkering, isn't building a home data center all about tinkering in the first place? Besides, I have already written a Cloudflare tutorial series. As long as you calm down, read it carefully, follow the steps, and figure things out on your own, I believe you can achieve great results.
Domain name ICP filing, using domestic CDN (requires home broadband to have a public IP address)
Compared to the first method, the advantage of this approach is that there is no high technical barrier—anyone can do it, which saves the time cost of learning many prerequisite technologies, and the access experience is the best for domestic visitors. However, the disadvantage is the time cost of dealing with hassles: ICP filing, as well as higher financial costs: purchasing a cloud server (because ICP filing requires your published resources to land on a controllable domestic institution).
a. ICP Filing
For individuals, the most convenient way to complete the ICP filing is to purchase a cloud server (Tencent Cloud, Alibaba Cloud, or others) and then file through the ICP filing system provided by the cloud provider. The benefit of this method is that the provider's filing department will help you review the filing materials, tell you what needs to be modified, notify you of any issues during regular inspections, and even tell you how to handle them~
b、购买云主机
购买云主机一般是腾讯云和阿里云,当然也有其他的,不过这2个规模最大,是主流选择,而在这2个云供应商购买主机以后备案也很方便,所以我就在腾讯云购买了最便宜的轻量服务器(2核2G内存,50g硬盘,4兆带宽,一个月300g流量,有新手优惠,便宜~,优惠下来差不多一个月9元,我勉强承受得起)。这个服务器性能一般,不太可能用来跑太耗资源的应用和数据库等,但是可以用来跑一些轻量级应用和演示内容。
c、选择合适的国内CDN
只要域名是备案的,就可以任意选择国内的CDN供应商了,而不是非要选择你购买云主机的供应商。
选择CDN的关键标准是家庭宽带公网地址的类型:如果是IPv4公网地址,则随便选择哪个都行,就看哪家流量价格低;如果是IPv6地址,只能选择支持IPv6回源的CDN厂家(例如阿里云CDN)。
注:其实还有一种刁钻的建站方式是把这个轻量服务器作为一级反代,上游服务器指向家里的二级反代,但是这种方式的访问体验会受限于服务器的上行带宽,且要求家庭宽带有公网地址。
不过也有变种方案:上游服务器是通过虚拟组网地址指向家里的设备,那么家庭宽带没有公网地址也可以;然后通过轻量服务器供应商的CDN服务(比如我就是使用的腾讯云的轻量服务器,就用腾讯云的CDN)来加速轻量服务器上网站的访问,这种方式就不受服务器上行带宽的限制(因为是同一个供应商的CDN来回源服务器,属于内部流量,没有带宽和流量的限制),但是受服务器下行带宽的影响(因为通过虚拟组网地址访问家里的二级反代,得到的相应内容对服务器而言是下行带宽,不过一般服务器下行带宽最少都有10兆,回个源足够了),适合想搭建家庭数据中心又没有公网IP又想使用国内CDN的朋友。
然后建议至少准备2个二级域名:
1、备案域名
用来给家庭数据中心应用对外(国内)发布使用(域名解析就放在腾讯云上),建议除非不得已,否则一切应用发布都通过CDN,家庭数据中心只是作为源站,这样可以隐藏家庭宽带真实的IP地址,毕竟国内CDN也可以通过一些简单的设置得到一定的安全性(高频访问限制、TLS版本限制等)。
2、未备案域名
再准备一个域名托管在cloudflare上,享受cloudflare的一条龙服务,同时也可以让备案域名通过自定义主机名来蹭cloudflare的服务。
Note: When an unfiled domain is hosted on Cloudflare, the 3rd-level subdomain of the filed domain can also connect to Cloudflare through the "custom hostname" method to enjoy Cloudflare's services. However, for domains connected using this method, Cloudflare only grants a 3-month validity period by default. Upon expiration, Cloudflare will check whether the SSL certificate of the connected domain itself is still valid. If it is, the validity period will be automatically extended by 3 months, and so on.
Preparing 2 domains has another benefit, which is that the home data center can have 2 entry points: one dedicated to domestic use (filed domain, domestic CDN), and one dedicated to overseas use (unfiled domain, Cloudflare). Meanwhile, if domestic access becomes unavailable due to force majeure (ICP filing invalidation?), the domain used domestically can be easily migrated to Cloudflare to remain active (the speed might be a bit slower, but at least access is guaranteed; of course, if you have great skills and love to tinker, the speed won't be too much slower~).
Finally, the core part of the home data center: the data center with home broadband as its egress. This part involves soft routing, virtual machines, LXC (Linux containers), the construction of various Docker applications, bastion host configuration, web application firewall setup, application health checks and failure alarms, application load balancing, databases, self-built gaming platforms, self-built media libraries, operations and troubleshooting, and many other aspects. A very key point in this part is: absolutely no spending money! After all, this is driven by my own interest, and as a flexibly employed person, I have no money to spare! The previous purchases of domains, cloud servers, and CDNs are considered necessary expenses that I cannot control, but the inside of the home data center is completely controllable, so everything chosen is free. However, free does not mean low quality; replacing financial investment with technical investment can still deliver a great experience in the end!
This series together forms the entire home data center solution (there is too much content, I will write it slowly later). Then thinking about it, organizing and summarizing project documentation is also very important, otherwise operations and troubleshooting will be very troublesome in the future, so I decided to start a blog to organize and record all the technologies and operating steps involved, which is how this blog came to be.