Changes to NatVPS

12345679»

Comments

  • @jmaxwell said:
    Any BF offers for credits ?

    Not currently, we tried to get an offer together for yesterday but we still have a few things to tidy up first. We will have an offer soon.

    @mee2 said:
    @natvps_uk How about Black Friday offer for UK NAT? We never had one like for FR NAT.

    We’re no longer selling individual VPS’ the amount of support required for a £1 per year VPS simply made it not worthwhile. Micronode instances are currently available and we may even have an offer soon.> @cybertech said:

    MOARRRRRRRRRR

    Soon hopefully!

  • @natvps_uk said:
    Memory editing is now live in almost all locations.

    🤟

    Waiting for storage editing and loadbalancer editing.

    We’re no longer selling individual VPS

    Time to delete the unsightly You currently do not have any MicroNode Virtual Private Servers section?

    We accept Karma donations for the last flan. 🍮 affbrr

  • @yoursunny said:

    @natvps_uk said:
    Memory editing is now live in almost all locations.

    🤟

    Waiting for storage editing and loadbalancer editing.

    We’re no longer selling individual VPS

    Time to delete the unsightly You currently do not have any MicroNode Virtual Private Servers section?

    In time, we still have a fair few VPS customers. We're not stopping renewals we just won't be selling anymore.

  • @jmaxwell said:
    Any BF offers for credits ?

    There is now :)

  • The Micronode panel is currently going through a rewrite to add some requested features.

    It’s currently written in PHP which I have regretted since launch. I’m rewriting it in Python (django) and I’m at a bit of a loss on what to do with the existing VPS line of services. There’s a lot of logic in the panel around VPS’ and a fair amount of it isn’t reusable for instances. It’s also two things to maintain that effectively serve the same purpose.

    Most clients have moved to instance credits but we still have around 200 VPS clients with active services.

    This isn’t something that’s going to be finished overnight, in fact it’s likely several months away at this stage.

    The idea I have currently is we allocate all active VPS Customers at least a single instance credit and convert their VPS’ to instances.

    I feel this is pretty fair considering most individual VPS’ are around 128-256mb RAM and 6-20GB disk. Everyone will end up with more resources for this transition period.

    We’d make sure the specs were matched so nobody would lose out.

    The downside is when it comes to renewal of these services we would not be able to honour the VPS pricing. We would offer a discount but it’s likely to be around the £10 per year mark for 512MB RAM and 20GB disk.

    I’m keen to hear people’s thoughts on this, nothing is set in stone and my mind can be changed.

  • @natvps_uk said:
    The idea I have currently is we allocate all active VPS Customers at least a single instance credit and convert their VPS’ to instances.

    There was a half-credit product last year.
    VPS of less than 256MB and 10GB could be converted to half-credit, renews at £5 that is closer to VPS pricing.
    They can open a ticket to upgrade to 1-credit for £10.

    We accept Karma donations for the last flan. 🍮 affbrr

  • @yoursunny said:

    @natvps_uk said:
    The idea I have currently is we allocate all active VPS Customers at least a single instance credit and convert their VPS’ to instances.

    There was a half-credit product last year.
    VPS of less than 256MB and 10GB could be converted to half-credit, renews at £5 that is closer to VPS pricing.
    They can open a ticket to upgrade to 1-credit for £10.

    That could be an option, the issue is a lot of the VPS’ are on the UK nodes which are HDD and a fair amount of the packages have a large amount of disk. Obviously this doesn’t scale well when all other locations are on SSDs.

    I think the safer option would be to migrate everyone to a full credit with the option to downsize at renewal via a ticket.

  • @natvps_uk said:
    a lot of the VPS’ are on the UK nodes which are HDD and a fair amount of the packages have a large amount of disk.

    Make a UK-HDD location with double/triple/quadruple storage, and a UK-SSD location with normal amount of storage.
    You can then convert an existing VPS to fewer credits.

    As an Instance-only user, so far I avoided UK because it's labeled as HDD that I perceive to have less value.
    If UK-HDD would have double storage, I may start using it.

    We accept Karma donations for the last flan. 🍮 affbrr

  • NeoonNeoon OG
    edited November 2023

    If you got different Node sizes and Types, I would advertise a minimum disk size, depending on Location you might get more for example if its SSD.
    So you would not have to bother with that.

    Pick the Language you like or can code best in.
    Ideally you pick the Language which is best for the Application, optional though.

    Python or PHP isn't terrible, I use booth depending on use case.
    I would suggest you try to refactor your existing panel, otherwise you have to deal with all the overhead migrating people again.

    Not to speak of, writing everything again from scratch.
    I might be able to help you, however can't make any guarantees.

  • Started adding billing and support tickets to the new panel. Here's a preview. The UI isn't finalised at all and a fair few changes are yet to be made. Its starting to come together though.

  • The worker on the AMS Loadbalancer crashed an hour or two ago, I've brought it back online now.

    If anyone has created a LB in the last few hours you may need to delete it and recreate it.

    We'll be adding further redundancy to Loadbalancers once we get the new panel live.

  • Hi there, will Debian 12 be available on Storage VPS instances in the near future?

  • @alexxgg said:
    Hi there, will Debian 12 be available on Storage VPS instances in the near future?

    Not as such, the storage VPS lineup is likely going to be replaced when our new panel goes live and it will be available then.

    This is likely to occur towards the end of January.

  • Not as such, the storage VPS lineup is likely going to be replaced when our new panel goes live and it will be available then.
    This is likely to occur towards the end of January.

    Good to hear that. Great services, keep it up.

  • @natvps_uk said:
    The worker on the AMS Loadbalancer crashed an hour or two ago, I've brought it back online now.

    I feel I'm guilty of breaking the poor worker.
    I deleted a loadbalancer and immediately re-created it with a different backend.
    Changes didn't apply after an hour and I didn't read this forum, so I moved the webapp to another provider for now.

    @natvps_uk said:
    Todo:

    Loadbalancer creation and Editing

    I'm glad that loadbalancer editing will come in the next panel version.
    This would eliminate the need of deleting and immediately re-creating.

    We accept Karma donations for the last flan. 🍮 affbrr

  • @yoursunny said:

    @natvps_uk said:
    The worker on the AMS Loadbalancer crashed an hour or two ago, I've brought it back online now.

    I feel I'm guilty of breaking the poor worker.
    I deleted a loadbalancer and immediately re-created it with a different backend.
    Changes didn't apply after an hour and I didn't read this forum, so I moved the webapp to another provider for now.

    It was actually dead at the time you deleted the LB, certbot had hung and consumed 8GB RAM causing the worker to be OOM killed.

    @natvps_uk said:
    Todo:

    Loadbalancer creation and Editing

    I'm glad that loadbalancer editing will come in the next panel version.
    This would eliminate the need of deleting and immediately re-creating.

    Going to try to add an LB in APAC and the US as well as a fair few clients are loadbalancing traffic from Canada and Korea over the LB located in Amsterdam.

    In fact I might just grab an additional IPv4 address in each of our locations and stick an LB on every node. I’ll have to think it over before committing to it.

  • Have you considered doing https passthrough?
    Works via the SNI, which provides the domain/target in plain text.

    However doesn't work with ESNI.

  • @Neoon said:
    Have you considered doing https passthrough?
    Works via the SNI, which provides the domain/target in plain text.

    However doesn't work with ESNI.

    I considered adding it as an option, we actually did this on the old proxy service back when we were on solusVM. It worked but had a few limitations.

  • @natvps_uk said:
    certbot had hung and consumed 8GB RAM causing the worker to be OOM killed.

    certbot is too inefficient.
    Nowadays I use acme.sh when I need a standalone ACME client.

    @natvps_uk said:

    @Neoon said:
    Have you considered doing https passthrough?
    Works via the SNI, which provides the domain/target in plain text.

    However doesn't work with ESNI.

    I considered adding it as an option, we actually did this on the old proxy service back when we were on solusVM. It worked but had a few limitations.

    HTTPS to HTTP (current loadbalancer, Flexible on Cloudflare):

    • Saves memory in my container because I don't need to run ACME client.
    • Insecure: traffic between loadbalancer and my container is in plaintext.

    HTTPS to self-signed HTTPS (Full on Cloudflare):

    • I don't need ACME client but can use self-signed certificate.
    • Medium security: Traffic between loadbalancer and my container is encrypted, eavesdropper cannot see it but MITM can modify it.

    HTTPS passthrough (microLXC):

    • I need ACME client or otherwise upload TLS key.
    • Secure: Traffic between loadbalancer and my container is encrypted, MITM cannot see or modify it.

    I'd like to see all three modes supported.
    Most frequently I use the second mode.

    We accept Karma donations for the last flan. 🍮 affbrr

  • Is the Romanian node officially gone or it’s just being “Calin’s server”

    Why?

  • @jmaxwell said:
    Is the Romanian node officially gone or it’s just being “Calin’s server”

    It’s been pretty unstable to the point that we don’t really monitor it. I just fix it every few days. I think it’s up right now though.
    The public IP did change recently, make sure you’ve got the right IP in the panel.

  • Billing Panel and Control Panel Migration Announcement
    Whilst we don't have a definitive date for this due to ongoing development at some point around mid January to Mid February we will be migrating away from the current billing panel and control panel to the new Micronode Panel which combines both aspects.

    This massively improves the user experience and simplifies administration.

    There will be no downtime for any Instances or VPS' although we expect around 3 days downtime on the Billing and Control panel, this will be communicated ahead of time to ensure that users can create instances or perform maintenance in advance.

    Notice to users with VPS'
    All VPS' will be converted to instances with the same specifications, a single instance credit will be assigned for all VPS users for the remainder of the billing period (512MB RAM and 20GB disk unless the VPS is larger where an additional credit will be assigned).

    Notice to users with Storage VPS'
    We will reach out to you ahead of time as this migration will involve downtime and a few operational differences.

    The new panel

    The new panel is written from the ground up, we've made huge UI improvements, added support for additional templates, introduced 2FA, Email verification and a higher level of fraud detection.

    Breaking Changes:
    * Password based SSH Auth has been removed, users will be required to add an SSH key for provisioning
    * Hostnames are now automatically generated
    * All locations come with the same resources (Double resource locations etc no longer come with double resources.)

    Improvements:
    * Loadbalancer Editing
    * One panel for Billing and Administration
    * 2fa
    * Email Notifications
    * Monitoring
    * Faster Provisioning
    * UI Improvements

    Screenshots:

    Instance Management:

    Memory Upgrade / Downgrade:

    Instance Details:

    Launch Instance:

    SSH Key Management:

    Add SSH Key:

    Products:

    Checkout:

    My Resources:

    View Tickets:

    Open Ticket:

    Reply/View Ticket:

    The public Beta will begin in the New Year, I'm going to be having some time away from development over the next few weeks to spend time with Friends and Family. We wish everyone an early Merry Christmas and a Happy New Year>

    If you would like to join the public beta you must already have a Micronode Account with active resources, please DM me on here and we will arrange early access.

  • Do a closed/public test before you migrate everybody, otherwise it may be ugly.

  • @Neoon said:
    Do a closed/public test before you migrate everybody, otherwise it may be ugly.

    As above, the beta will begin early January.

    The public Beta will begin in the New Year, I'm going to be having some time away from development over the next few weeks to spend time with Friends and Family. We wish everyone an early Merry Christmas and a Happy New Year>

    If you would like to join the public beta you must already have a Micronode Account with active resources, please DM me on here and we will arrange early access.

  • AuroraZeroAuroraZero Retired
    edited December 2023

    So who is the auditor?

    The Yeti has left the building.

  • @AuroraZero said:
    So who is the auditor?

    The code will be reviewed prior to release externally along with a pen test. I can’t share details on this currently as we haven’t yet awarded the contract.

    This will likely not occur prior to the beta and this will be stipulated in the beta terms and conditions, no data personal data will be stored in the panel during the beta period and the panel will not be connected to any of our production nodes.

  • @natvps_uk said:

    @Neoon said:
    Do a closed/public test before you migrate everybody, otherwise it may be ugly.

    As above, the beta will begin early January.

  • My VPS in Limburg got suspended due to "Torrent Activity Detected" yesterday. I don't use it to download torrents or anything related. When I logged in to the client area, I found that there's another (unrelated) ticket open for more than a month.

    Has anyone else been erroneously suspended before?

    dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/

  • @Brueggus said:
    My VPS in Limburg got suspended due to "Torrent Activity Detected" yesterday. I don't use it to download torrents or anything related.

    Torrent detection is an automated process, for context it was somewhat forced upon us from one of our providers to prevent the nodes from being suspended. I can't go into the full logic of what the detection is doing but the first condition that must be met is a number of TCP packets containing the bittorrent header must be detected either originating from or with a destination of either your IPV4 port range or IPv6 Address.

    If your VPS is being used as a VPN any torrent traffic going over the VPN will also trigger this.

    Thats not to say that we haven't seen false positives although I can say that less than 1% of our VPS' have been hit with a torrent suspension over the last 12 months and only a tiny number of them have been false positives.

    Without fully understanding what was happening on your VPS at the time I can't categorically say what caused this although I have now unsuspended your VPS - you will need to reboot it from the panel.

    To help debug this in the future the suspension warning in the upcoming panel will show the SRC and DST IP and port of the activity determined to be torrent based.

    @Brueggus said: When I logged in to the client area, I found that there's another (unrelated) ticket open for more than a month.

    We've always been clear that this service comes with limited/no support. We do tend to work through tickets in batches and we do a ticket sweep once per day to ensure that no clients are facing downtime.

    @Brueggus said:
    My VPS in Limburg got suspended due to "Torrent Activity Detected" yesterday. I don't use it to download torrents or anything related. When I logged in to the client area, I found that there's another (unrelated) ticket open for more than a month.

    Has anyone else been erroneously suspended before?

    As far as I'm aware out of the 800+ clients we have only one other user has seen false detection and we are working on a solution for their use case.

  • @Brueggus said:
    My VPS in Limburg got suspended due to "Torrent Activity Detected" yesterday. I don't use it to download torrents or anything related. When I logged in to the client area, I found that there's another (unrelated) ticket open for more than a month.

    Has anyone else been erroneously suspended before?

    I'm having these problems too. I created a support ticket and we're still in investigation what cause these issues. On my vps I never used any torrents and never will.

  • @natvps_uk said:
    Torrent detection is an automated process, for context it was somewhat forced upon us from one of our providers to prevent the nodes from being suspended. I can't go into the full logic of what the detection is doing but the first condition that must be met is a number of TCP packets containing the bittorrent header must be detected either originating from or with a destination of either your IPV4 port range or IPv6 Address.

    An attacker can get everyone suspended by:

    1. Scan for open TCP ports.
    2. Send a BitTorrent header to each open TCP port.

    Your detection logic needs to check for whether the container responded to the incoming BitTorrent header in a way that BitTorrent software would.

    We accept Karma donations for the last flan. 🍮 affbrr

  • @yoursunny said: Your detection logic needs to check for whether the container responded to the incoming BitTorrent header in a way that BitTorrent software would.

    I'm not able to go into details on this but this is accounted for. We didn't write the tooling, it was provided to us.

    I plan to move to more of a traffic blocking approach to discourage torrenting VS Suspension.

  • edited December 2023

    I was one of the user that false positives causing vps suspended from half years ago,and they just unsuspended the vps 1-2months ago(after few months of two ticket opened).
    And i can 100% confirmed the detection logic is not working correctly, as i never install any torrenting app on it,even vpn application like wireguard. (And the vps was suspended after few days of vps provision)
    The only thing i "might" install was Alist(From Github),as i cant remember any else was installed on that suspended vps.

    Edited:
    They just unsuspended the vps,and only allow to reprovision the vps with blank new data,so i cant check what was the main reason on the vps causing the false positive.

    MY/SG & Worldwide Latency Test V3 : http://www.mywebping.com (27 February 2021 Updated)
    MY-Unifi Home SmokePing: http://smokeping.mywebping.com/smokeping/

  • @go626201 said:
    I was one of the user that false positives causing vps suspended from half years ago,and they just unsuspended the vps 1-2months ago(after few months of two ticket opened).
    And i can 100% confirmed the detection logic is not working correctly, as i never install any torrenting app on it,even vpn application like wireguard. (And the vps was suspended after few days of vps provision)
    The only thing i "might" install was Alist(From Github),as i cant remember any else was installed on that suspended vps.

    This will get better, the new panel automatically unsuspends after 24 hours which will prevent people being left in the dark.

  • edited December 2023

    Suspension script should provide a pcap of offending packets.
    Customer who thinks they experienced victimisation could upload the pcap for all to judge whether they are indeed torrenting.

    We accept Karma donations for the last flan. 🍮 affbrr

  • @yoursunny said:
    Panel should provide a pcap of offending packets.
    Customer who thinks they experienced victimisation could upload the pcap for all to judge whether they are indeed torrenting.

    We’ll start with the src and dst ports and IPs. I’d rather put the effort into moving away from suspension and just try to prevent it via blocking torrent downloads. That’s an easier said than done mind as there’s a lot to consider there.

  • edited December 2023

    @natvps_uk said:

    @yoursunny said:
    Panel should provide a pcap of offending packets.
    Customer who thinks they experienced victimisation could upload the pcap for all to judge whether they are indeed torrenting.

    We’ll start with the src and dst ports and IPs. I’d rather put the effort into moving away from suspension and just try to prevent it via blocking torrent downloads. That’s an easier said than done mind as there’s a lot to consider there.

    In my undergraduate, I participated in a research program that studies how to restrict BitTorrent and eDonkey.
    I don't understand the details as I only built an UI.
    The grad student in charge of the project said it's based on pattern matching in the packets, implemented through iptables l7filter module.
    As soon a matching string is found in the packet, that packet is dropped.
    In the demo, we can see BitComet shows zero speed when the blocker is enabled.
    I don't know how much overhead this would cause though.

    I read some other papers at that time.
    One other technique is counting the number of TCP connections versus the number of remote IPs.
    If a particular local IP:port has made many TCP connections but there's only one connection per remote IP, this port is engaging in torrenting.

    Boss made me implement this method on the office router.
    Whoever found torrenting during work hours would be called into the boss office.
    Torrenting is legal in China but it's not okay to cause a congestion during work hours.

    We accept Karma donations for the last flan. 🍮 affbrr

Sign In or Register to comment.