"Set nginx worker_processes to your core count"
Half-right and outdated. Just use
Default 768 means 1 vCPU caps at ~768 concurrent. Bump it:
—
—
Also raise the OS limit or nginx silently caps. One $5 vCPU served 8k concurrent for me after this.
Try it tonight.
Half-right and outdated. Just use
worker_processes auto; — it reads cores itself. The real bottleneck nobody mentions is worker_connections.Default 768 means 1 vCPU caps at ~768 concurrent. Bump it:
—
worker_connections 4096;—
worker_rlimit_nofile 8192;Also raise the OS limit or nginx silently caps. One $5 vCPU served 8k concurrent for me after this.
Try it tonight.
rsync vs restic for backups
rsync mirrors files fast and you can read the result with any tool — but it's not real versioning; an oops overwrites your only copy.
restic does deduplicated, encrypted, snapshot backups straight to cheap S3/B2.
— Quick local mirror to a second disk: rsync
— Versioned offsite backups, ransomware-proof: restic
B2 storage runs ~$6/TB/month, restic dedupes so you pay for almost nothing. Mirror locally, snapshot offsite. Try it tonight.
rsync mirrors files fast and you can read the result with any tool — but it's not real versioning; an oops overwrites your only copy.
restic does deduplicated, encrypted, snapshot backups straight to cheap S3/B2.
— Quick local mirror to a second disk: rsync
— Versioned offsite backups, ransomware-proof: restic
B2 storage runs ~$6/TB/month, restic dedupes so you pay for almost nothing. Mirror locally, snapshot offsite. Try it tonight.
"Behind Cloudflare so I don't need a firewall"
Your origin IP leaks — old DNS records, mail headers, SSL cert logs (crt.sh). Once found, attackers hit your IP direct and bypass Cloudflare entirely.
Lock the origin to only accept Cloudflare:
—
— allow only Cloudflare's IP ranges on 443
— pull the list from their published ranges, script a cron to refresh
Now direct hits get dropped at the door. Try it tonight.
Your origin IP leaks — old DNS records, mail headers, SSL cert logs (crt.sh). Once found, attackers hit your IP direct and bypass Cloudflare entirely.
Lock the origin to only accept Cloudflare:
—
ufw default deny incoming— allow only Cloudflare's IP ranges on 443
— pull the list from their published ranges, script a cron to refresh
Now direct hits get dropped at the door. Try it tonight.
First 10 minutes on a fresh $4 VPS
Just spun up a new box. Before I touch nginx I do this in order, every time:
—
—
— In
—
—
Clean slate, no root password to brute. Try it tonight.
Just spun up a new box. Before I touch nginx I do this in order, every time:
—
adduser deploy && usermod -aG sudo deploy (kill root login next)—
ssh-copy-id deploy@IP then test the login in a SECOND terminal— In
/etc/ssh/sshd_config: PermitRootLogin no, PasswordAuthentication no—
systemctl restart ssh — keep the first terminal open in case you lock yourself out—
apt update && apt upgrade -y && rebootClean slate, no root password to brute. Try it tonight.
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
На Anthropic, OpenAI, Google и SpaceXAI подали в суд из-за ИИ
В Калифорнии против ИИ-компаний подали антимонопольный иск: регулятору показалось подозрительным, что игроки синхронно призывают ограничить развитие нейросетей ради безопасности. Смысл спора в том, что инвестиции в ИИ уже обгоняют реальный прогресс, а бизнесу выгодны правила, которые защитят капитал. Вывод: быстрых прорывов ждать не стоит, лучше выжимать максимум из текущих инструментов.
➡️ Читайте на сайте: https://aff.top/blog/na-anthropic-openai-google-i-spacexai-podali-v-sud-iz-za-ii
🧠 Ещё больше инсайтов → в канале AFF.top
В Калифорнии против ИИ-компаний подали антимонопольный иск: регулятору показалось подозрительным, что игроки синхронно призывают ограничить развитие нейросетей ради безопасности. Смысл спора в том, что инвестиции в ИИ уже обгоняют реальный прогресс, а бизнесу выгодны правила, которые защитят капитал. Вывод: быстрых прорывов ждать не стоит, лучше выжимать максимум из текущих инструментов.
➡️ Читайте на сайте: https://aff.top/blog/na-anthropic-openai-google-i-spacexai-podali-v-sud-iz-za-ii
🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from AffPapa! Клуб спящих бизнесменов! Потрачено!
This media is not supported in your browser
VIEW IN TELEGRAM
🔥 Приватные консультации по запускам Google ads и FB.
Масштабное обновление материала на сентябрь,без воды и паблика,свежий пак информации для опытных баеров(техничка,разбан,модерация,
связки,масштабирование и т.д)
Полный пак:
https://t.me/googleadsroi/164558
Отзывы:
https://t.me/+jnxGdX6GbjgxZTQx
Аккаунты гугл адс:
https://t.me/+VCIrjC36UiYyYjM0
Мой контакт:@TRAFF3
гарант+По промокоду( #affpapa ) скидка -10% на все услуги.
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Google ads начал показывать расходы конкурентов
Google Ads запустил Peer Spending — инструмент, который сравнивает расходы аккаунта с рекламодателями из той же ниши без раскрытия чужих данных. Он показывает, тратите вы больше, меньше или примерно на уровне конкурентов на уровне кампаний и групп объявлений. Для арбитража это скорее ориентир по бенчмаркам, чем инструмент прямого усиления залива.
➡️ Читайте на сайте: https://aff.top/blog/google-ads-nachal-pokazyvat-raskhody-konkurentov
🧠 Ещё больше инсайтов → в канале AFF.top
Google Ads запустил Peer Spending — инструмент, который сравнивает расходы аккаунта с рекламодателями из той же ниши без раскрытия чужих данных. Он показывает, тратите вы больше, меньше или примерно на уровне конкурентов на уровне кампаний и групп объявлений. Для арбитража это скорее ориентир по бенчмаркам, чем инструмент прямого усиления залива.
➡️ Читайте на сайте: https://aff.top/blog/google-ads-nachal-pokazyvat-raskhody-konkurentov
🧠 Ещё больше инсайтов → в канале AFF.top
Hunt the RAM hog in 3 commands
Box at 95% memory and you don't know why. My triage order:
—
— Real offenders:
— Per-process truth (shared memory counted once):
— MySQL usually wins. Drop
Know your real headroom before you upsize the plan. Try it tonight.
Box at 95% memory and you don't know why. My triage order:
—
free -h first — if buff/cache is high that's FINE, Linux uses free RAM as cache, ignore it— Real offenders:
ps aux --sort=-%mem | head -5— Per-process truth (shared memory counted once):
smem -tk -c 'name pss' | sort -k2 -h | tail— MySQL usually wins. Drop
innodb_buffer_pool_size to 128M on a tiny box and reclaim 300MB instantlyKnow your real headroom before you upsize the plan. Try it tonight.
"Set innodb_buffer_pool_size to 80% of RAM"
That rule is for dedicated DB servers. On a $5 LEMP box where PHP-FPM, nginx AND MySQL share 2GB, 80% means instant OOM.
Reality on a shared box: size it to your actual data, not your RAM. Check it:
If your DB is 300MB, a 512MB pool caches everything. Save the rest for everything else.
Try it tonight.
That rule is for dedicated DB servers. On a $5 LEMP box where PHP-FPM, nginx AND MySQL share 2GB, 80% means instant OOM.
Reality on a shared box: size it to your actual data, not your RAM. Check it:
SELECT table_schema, SUM(data_length+index_length)/1024/1024 FROM information_schema.tables GROUP BY 1;If your DB is 300MB, a 512MB pool caches everything. Save the rest for everything else.
Try it tonight.
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Минфин РФ планирует выпустить собственный стейблкоин
Власти РФ обсуждают запуск рублёвого стейблкоина: сейчас решают, как его обеспечить, какие операции разрешить и будет ли на него спрос. Основной кейс — международные переводы, а не использование физлицами. Если проект доведут до запуска, он может стать частью новой криптоинфраструктуры и альтернативой токенам, привязанным к дружественным валютам.
➡️ Читайте на сайте: https://aff.top/blog/minfin-rf-planiruet-vypustit-sobstvennyi-steiblkoin
🧠 Ещё больше инсайтов → в канале AFF.top
Власти РФ обсуждают запуск рублёвого стейблкоина: сейчас решают, как его обеспечить, какие операции разрешить и будет ли на него спрос. Основной кейс — международные переводы, а не использование физлицами. Если проект доведут до запуска, он может стать частью новой криптоинфраструктуры и альтернативой токенам, привязанным к дружественным валютам.
➡️ Читайте на сайте: https://aff.top/blog/minfin-rf-planiruet-vypustit-sobstvennyi-steiblkoin
🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
В публичный доступ вышел Grok 4.7
➡️ Читайте на сайте: https://aff.top/blog/v-publichnyi-dostup-vyshel-grok-4-7
🧠 Ещё больше инсайтов → в канале AFF.top
➡️ Читайте на сайте: https://aff.top/blog/v-publichnyi-dostup-vyshel-grok-4-7
🧠 Ещё больше инсайтов → в канале AFF.top
"Changing SSH port is security theater"
The purists love saying this. They're wrong about what it's for. It's not encryption — it's noise reduction. Moving off 22 drops automated scan attempts ~95%.
That matters: clean auth logs mean fail2ban and your alerts actually surface real targeted attacks instead of drowning in bot spray.
Defense in depth isn't theater. Quieter logs = sharper eyes. Try it tonight.
The purists love saying this. They're wrong about what it's for. It's not encryption — it's noise reduction. Moving off 22 drops automated scan attempts ~95%.
That matters: clean auth logs mean fail2ban and your alerts actually surface real targeted attacks instead of drowning in bot spray.
Port 2202 + key-only auth + AllowUsers deploy.Defense in depth isn't theater. Quieter logs = sharper eyes. Try it tonight.
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
X теперь показывает причину теневого бана
➡️ Читайте на сайте: https://aff.top/blog/x-teper-pokazyvaet-prichinu-tenevogo-bana
🧠 Ещё больше инсайтов → в канале AFF.top
➡️ Читайте на сайте: https://aff.top/blog/x-teper-pokazyvaet-prichinu-tenevogo-bana
🧠 Ещё больше инсайтов → в канале AFF.top