At first, I self-hosted email on home server. Paid extra for a dedicated IPv4 address in the cable broadband bill at a residence.
I then started dealing with critical business emails, and a single server at the house is not reliable for that so I migrated to semi-self-hosted by paying for business-class email package. I still use my custom domain and point the DNS MX records the the hosting company's server. That was 15 years ago and had a few family & friends also use that for email.
But I'm now in the process of getting everyone off my email server except for me and migrating them to GMail and Microsoft 365 Outlook. They need simple reliable email and my 1-man-army of IT staff (me & myself & I) cannot support them if I'm in the hospital for a month.
My custom email setup has "too many moving parts". There's a login in at the registrar to constantly renew the domain. And there's another login at the hosting company and pay that yearly bill with a credit card. There are multiple points of failure. I'm the proverbial "if he gets hit by a bus" problem: https://en.wikipedia.org/wiki/Bus_factor
No, I can't write up some documentation with screenshots so they know how to navigate the process at the registrar and hosting company. E.g. if they try to login from their "unrecognized" computer to takeover email administrator tasks, a 2FA email confirmation with random 6-digit code would be sent to guess where? To _my_ email, not theirs. The interconnected dependencies are complicated and invisible because the recovery procedures are not stress-tested. Besides, the web UI changes constantly at those companies so the "oh shit what do I do" documentation would quickly get out of date anyway.
The redditor's story just reinforces my decision to not let people depend on my email server anymore.
If you're hosting email for family & friends, carefully think through all possible failure modes so they're not in trouble if you're not around.
Everyone in my family has their own domain. The instructions for renewing a domain, a list of reputable mail service providers, and instructions for pointing MX records at a new service provider, are not very complicated for somebody that can work a computer at a basic level of productivity. Many email service providers will even run nameservers on your behalf so you don’t even have to mess with individual DNS records. You can fit that in about one formatted page of instructions to include in your online contingency plan you share with love one(s).
I also don’t know why GP has to “log in at the registrar to constantly renew the domain”. Auto-renewal exists. I haven’t lifted a finger for any of my domains for many years.
* All mails are on Gmail or iCloud.
* All backups are on Dropbox and iCloud.
* All photos are on iCloud shared folders.
* All passwords and secret notes are on 1password.
And I made sure that I am not the only admin. Life is simpler this way. I wrote detailed instructions on how to recover all these in my will in 1password.
Today I'm married to a different person and still administering email for my ex. Out of everything that came of that relationship, I regret the email server the most.
So you set up an email account specifically for those, and put the credentials for it in the documentation. You probably want that to be hosted somewhere else though, because needing the code to access your email system so you can get the code is not a fun kind of circular dependency.
That's not limited to self-hosting though. You lose your device and therefore the saved password for Provider A, to reset it they want to send a code to Provider B, to sign into that they want to send a code to Provider A. 2FA circular dependencies are actually kind of a scourge.
A Yubikey as 2FA is another good option but that is not widely supported yet.
Add another phone line for a phone that stays home and is the 2FA phone (or a Google Voice to a shared email account, with all family members phones as the Gmail 2FA, since it supports multiple phones)
#1 rule, pay for domains out the full 10 years, every year, everything else is gravy. As long as your estate owns the domain, things can be fixed even if some mail is lost. They have a decade to sort it out ;)
This happens to me a few times per year and is enough of a hassle to get me to want to get off of this forwarding service.
It's infuriating how everyone in the world is doing this forced 2FA stuff now.
I've tried to mitigate this risk by keeping a so-called "death book": a hardcopy of all accounts, passwords, 2 factor auth instructions, router SSIDs, and so on, kept in the firesafe with all the other important stuff. But this Reddit post points out that this is not enough! Someone would also have to come in and take over the technical toil and maintenance that it takes to keep everything running. Not sure what the solution is. The rest of my family has no interest in learning this stuff. They can't even remember their own passwords without me, let alone ssh to our VPS and restart exim4.
When a coworker (IT staff, in your case) leaves, they get replaced.
Family just leaves a hole. Maybe some duties get taken over, maybe not. You may leave behind an IT shaped hole, but it's not really a new or unique problem. You lose the person who organized the holidays, the family reunions, the one who made the good pie, the peacemaker who kept the half-dozen warring factions cordial.
Maybe someone else steps up. Maybe not. It just gets rolled into the larger grieving process of the holes left by those we've lost.
My wife knows what hard copies (my "death book") to give him if necessary. Until I die he has no access, but once I do he has my implicit trust.
I don't keep the documentation updated as often as I'd like, but it doesn't drift much between update sessions either. A life event usually prompts updating the docs. The last time I updated was the night before going in for surgery.
Besides my self-hosted stuff, I do "family IT" too. The "family IT" stuff is all documented just like one of our Customers. I made a point of insuring that my business partner could take on the family in the same way that he could take on other Customers. The goal is still probably to wind down, but it puts the family IT on somewhat similar footing to the Customers.
Yeah that's the problem. They may have the passwords etc. but they don't have the knowhow to understand how the Proxmox cluster works, why the scripts aren't running, or comprehend an obscure error. It's basically a business setup at this point and would require someone with an IT background and lots of time to understand. Hell if you suddenly gave me such a setup and asked me to figure it out it would take a lot of time and trial and error as well.
The thing though is that if something happens the stuff won't all go down at once, there will be a process where hardware fails, subscriptions aren't paid, and so forth. So what I tell my family is to immediately backup the NAS files to external HDDs, create new email accounts with a public and setup forwarding for as long as it lasts (while changing their bank/Facebook/etc. to use those new emails), and so on. The telephone/internet providers may need to be changed to a user friendly residental service.
And all that has to happen fast before everything becomes inaccessible.
Internet account - they'll file paperwork to get access. They can continue paying the bills. Same goes for all utility accounts and online services (most of which is not a big loss - they can sign up for their own Netflix account if need be!)
Router: That's the main failure point. But they can just replace it with one the ISP gives (for a fee, of course).
Email: I have my own setup, so no one is impacted if I die.
Self hosted stuff: I think I'm the only user. Wife was using Plex for a while but doesn't any more.
Smart home: Yeah, they'll lose this. Stuff like smart switches "just work". But smart bulbs occasionally need to be reset and resynced to the hub. All in all, it's not really a great problem if they start failing.
I did add notes to my will on what I felt were the important files on my PC they may want to preserve (photos, etc). They don't use Linux so they may need help extracting them. Easy to pay someone to do it, but I have a feeling they won't really bother.
What about going on strike for a day or two? Not in a petulant way, but in a loving way. Just to impress upon your family exactly how important things are, that they're currently taking for granted. Maybe you'd get a volunteer to do some modest training and succession planning.
Also when one partner dies or is ill, the other often lacks the capacity (mental etc) to deal with complex technical stuff.
We use Fastmail, Dropbox, etc with all service admin accounts in a shared family icloud keychain group [1]; all services are on autopay from a credit card that is automatically paid each month out of investment account, family email domain is paid up 10 years into the future. Any of our family members can check their mail or change configs through Fastmail's web UX.
[1] https://support.apple.com/guide/iphone/share-passwords-iphe6...
Apart from that, I am glad to see reddittors stepping up to help the guy. That's the good old internet.
BTW, if you work for a hosting company, do your processes actually to the above for a non-technical, grieving heir?
Most (all?) companies have some process where you show a death certificate and then get access to the account.
(in before "oh no! what if they steal your stuff! what if they leave your wife and kids with nothing and steal your money" i have two answers to that, get better friends of course is the main one. but the second one is that reason our mind goes in that direction is because there's been a lot of moral stories written, bulk of them in victorian times, of wives left destitute because of unscrupulous associates. those stories make for nice drama, and they are also warnings for individuals and society in general. you gotta trust someone, better be people i knew for a long time, rather than some random consultant from reddit, or a geek squad member)
If you have a loved one whose abandoned site will eventually die, consider spidering the site and turning it into a physical book. I don't know of any services that will do this for you but this is the only way family will have a chance to read their words in 20+ years.
If I want to migrate it to a new host or a new static site generator it's all pretty trivial. Theoretically outputting it to PDF or print should be pretty doable.
The one that was forgotten was his cellphone pin; would have been nice to get a copy of his photos (encrypted Samsung)
I constantly recommend the use of password manager and unique credentials everywhere (to prevent cred stuffing attacks). I always get feedback from friends/family that they worry about forgetting the password to the manager. I tell them to write it down and put it in their safe. And it always results in a deer-in-headlights response. They've been told for years to NEVER write down a password.
(aside: I still need to get those photos backed up into my home NAS).
We want to keep making things more shiny and complex because it justifies our jobs. But everything has dependencies, breaking changes, cruft. Working systems decay too fast. The software industry has become nothing but overhead and maintenance.
If this continues there's no future for it, that might sound impossible or unbelievable, but humans advance, and this isn't advancement, you can't run a space colony on software that stops working a year later and needs legacy system admins to keep the air running in 15 years. This stuff needs to normalize, slow down, become bedrock, or our civilizations will not be able to rely on it.
I still have a lot of home automation but I’ve specifically selected equipment that “fails normal” - the smart stuff like rules and voice control and so forth might go away, but the switch on the wall will continue to work regardless.
Finally I fanatically use a password manager. The password, backup key, etc for that is written on an “in case” letter stored in a fireproof/waterproof envelope in a fireproof safe in my home, and my family is aware of it.
It’s one of those unpleasant things to have to plan for, but I don’t want my family to have everything break on them if I die.
If I need help with some open source software, I can reach out to their community, point them to the repo, and show them exactly how to reproduce my issue.
And I just realized that when I am not around, my wife can still call my technical friends or find contractors to fix stuff, by submitting PRs to the repository. She just need to get my GitHub account from shared password manager and approve PRs ;)
This is why I refuse to touch “critical” things for self-hosting like email. If Home Assistant goes down then it’s not the end of the world. Physical switches still work and people can work around it. Same deal with a media server, it’s not the end of the world. Losing email/chat/photos IS the end of the world for a lot of people.
- All account passwords
- All financial account info etc
- Information on where pictures are stored on our home server.
- a message for her to read if I die.
My instructions for self hosting is basically “tear it down and give it away”
It helps that almost everything is in 1Password.
Dreamhost is $13/mo (although they have a temporary discount right now). That's more than $5/mo, but you get a lot more than email.
They also have email only hosting: $1.67/mo/mailbox if you prepay for a year.
I can see why you think the hosting companies are gouging you with their prices per user, but look at it from your family's perspective. Their email is probably worth a lot more than $2/mo to them, and if you suddenly die and they lose access, it would be because you didn't want to pay $2/mo to avoid that pain.