I usually connect with my server via ssh in a terminal and run basic commands. What’s a better, more efficient and modern way of doing that? Especially considering ai and documentation along the way? I wonder if there’s a better approach than “connect from remote and act local”. Is there a method to “code local and push to remote”?
I use a fedora server with podman, caddyfile and vi.
I spent a while getting Ansible to be able to setup and maintain my server(s). And ended up not using it as much as I should, mostly because the computer I used to run Ansible from became a “Steam Machine” so I’m rarely sitting on it with a keyboard now and I don’t want to have personal info and keys on my work computer.
But it was a good learning, and useful while I used it. Now I just use ssh and compose files directly.
My target is terraform to provide VMs on my miniPC and ansible to configure them. For my nas, probably a basic distro then some ansible stuff to setup stomate.
Usually I put handcuffs on her every night, to keep her off of me, and only feed her the highest grade sushi and meat. It keeps her hair shiny, keeps good health, and complaints down to a minimum. I make sure she gets adequate sleep on an expensive mattress while I sleep on a 2 inch futon on the floor.
Oh wait… wrong kind of server.
I ssh into it twice a year to perform updates but otherwise i leave it alone. Server’s been chugging along for like a decade now.
Twice a year is crazy. I suppose most of my maintainence is adding drives (I’m a creator and I definitely totally need to archive all of my footage), but I also run a fair few apps that have needed manual update steps, so I do all my updates manually so I can fix stuff if it breaks.
Similar, but you might want to update more frequently with the huge number of critical security bugs being discovered by AI recently
I have unattended upgrades configured
Hmm I need to figure out how to do that
If you are using aptitude (apt) it is quite simple: https://ubuntu.com/server/docs/how-to/software/automatic-updates/
If you just want security updates and are fine with the default configs:
# apt install unattended-upgrades
I’ll take the maverick and share my niche position. I did most if not all my proxmox setup and configuration via complete reliance on LLMs. Now, before anyone says “why would you do that”, and I’ll be straight up. I was high for all of it, and not a small blaze I’m talking regularly stoned for months. And I’ll say it “got me by” for the frame work. It worked? Sorta. Music, Plex, immich, docker, arr stack, podman. Now, I can’t say I fully understand it still and I’ve done a lot of changes since that point last year and I figured it out by asking the model to backtrack what we did and I wont lie it helped me better learn how to question the models for my job, and It did decent documnetation over my server. But again, I was literally high doing it
self hosted gitlab. each server has a repo with all the docker configs and application configs. also have any scripts for the server itself on there as well, things like required libs, network configs, etc.
I also have a repo dedicated for let’s encrypt SSL that retrieves new certs every month. then on each server is an install script scheduled that pulls the certs down, installs them, and restarts any services automatically.
should anything go wrong, I have a siem monitor that will alert me that a service failed to start etc.
currently running four servers like this with varying degrees of complexity.
“code local and push remote” is only more efficient if you have a faulty connection with ssh or want to use a GUI editor that doesn’t support remote connections. What you’re doing is good. You can scoure for more “modern” ways that might have more glimmer and sparkly lights, but it won’t improve efficiency.
Declarative configuration (like docker compose) is basically “code local, push remote”, and it has a lot of benefits, including improving efficiency because you have a clearer idea of exactly what is set up on the server, to make it easier to debug or make changes.
Contrast this with just sshing in and running a bunch of commands to install something. Then coming back months later and wondering “what files did I touch? what packagea did I install? Hmm dpkg log says I added X but then later I removed it, so was it important?” Etc.
I wait for something to break. Then I yell “God fucking dammit, I don’t have time for this right now!” and spend an hour triaging things before I just try docker down, pull, up and everything works.
same. or i just df and see / 100%
Early on I wrote a script for my user account to run df and save the output to a file, then a second script to read that file and if the drive was full send me an email.
First, it failed because it couldn’t send the email because the email service failed under full disk conditions.
Second, it failed because it couldn’t write the file to disk because the disk was full.
Third, it failed because outbound SMTP was blocked by my ISP.
I learned a lot about how well you can fail if you really put your mind to it. Now I have Home Assistant grabbing the disk stats for my machines and flagging anything over 90%.
Ansible is one way to “code local, push to remote(s)”. Can define so-called playbooks, which is basically just a script, to do reoccuring tasks like e.g. updates.
Ansible is great, I just wish it would automatically cleanup stuff on the server when I remove parts of the config. I know it’s not the goal, but I dream about a tool that works this way. I get many leftover stuff over years
We fixed that with roles that manage both install and uninstall
That works but that’s only useful if you have many machines. I have a single server so it’s the same burden as doing it manually. If only the uninstall step could be completely automated by just reverting the install step
To be fair to Ansible, that’s probably a packaging issue.
If the 1st run of an application creates a bunch of files and folders, then the packager won’t know about them and Ansible’s just relying on that.
But yeah, for 1 machine I’d find Ansible overkill (not a problem per se), but really helps when you have 5 Rasperry Pi Zeros scattered around the house 😉
Not quite, if you write the role to manage the life cycle of a bit of software then uninstall is part of that life cycle.
But I do see that investment in time looks more then just do it by hand
That sounds like NixOS to me.
I have yet to try it but apparently

Depends what you’re trying to do, really
If you’re talking about going in and restarting containers and checking logs, there are tools like Portainer that give a nice UI you can quickly use from your phone
If you’re talking about repetitive tasks, sometimes there’s a tool to automate it already (e.g. updates via watchtower, unattended-upgrades), and if not, you can write a script and possibly run it via a cronjob if that makes sense
If you’re talking about doing new stuff, you either stick with the SSH & shell commands, or you look into IaC tools like ansible as another reply mentioned. Another option is something like Nix where the setup is defined in config, so you make your changes there
nixos, mostly. It has a very steep learning curve but if it breaks I’m just “whatever, rollback now, fix properly later”.
If you’re connecting from a system that’s a long distance away from your server in terms of latency, mosh can be more comfortable to use than ssh.
Mosh is pretty good!
There are probably multiple flashy clients and gui’s for it, but if you’re already used to the terminal, I’d recommend
rsync. This might be the wrong syntax but something likersync -av ~/local/project servername:/var/www/html/would take your local files and update the web directory of your server with only the files that are more recent. Rsync will even read your ssh config file so if you’re got an entry for your server you can just use the host name.I ran a little blog for a while using a static site generator so I setup the git server on my web server and wrote a git hook where every time I pushed to the repo the server would pull it’s cloned copy of the repo into the html directory. Took me a few hours to setup but it made updating the blog as simple as pushing to the repo.
Nothing wrong with good old ssh. My VMs are different enough that building and maintaining ansible playbooks or something similar would be a bigger task than actually doing it in the traditional way. Maybe I could benefit by building simple playbooks to populate user accounts, ssh keys, smtp relay settings and other common things, but I don’t really set up new servers that often that it would justify spending time to set up tools for that.
Ansible and terraform can bath do with you want though for a single server I’d consider them both to be a somewhat overkill. But then again homelabbing often is about overkill.











