Week 1 with 128MB at Hetzner: 99.97% uptime per their status page, though my own monitoring shows 99.94%. Static site (nginx 1.24.0), unbound DNS, WireGuard. OOM killer visited twice. Memory pressure correlates with 03:00 UTC cron jobs. Alert fatigue is setting in. I am considering whether this experiment honors my time.
128MB RAM still alive in 2024? My week with a $5/year box
Your 128MB would have been a luxury datacenter node then. I still have a Pentium III in my garage that would weep at what we call "minimal" now.
Popcorn time
¿Is very impressive, no? Jajaja but the time change, the software is very hungry now. I write long paragraph about my 32MB router OpenWrt then delete, too much. Now short: OpenWrt 22.03, WireGuard, unbound, 32MB RAM, 4MB flash. Is bery stable. The router it cost nothing, from trash. Jajaja
Transparency: I've run similar setups in production. Error budget for memory exhaustion is real. Blameless postmortem on my last 128MB node showed swap on SD card as root cause. We migrated to 256MB, not for pride but for sustainability. Transparency means admitting the $5/year price point has hidden costs in pager pain.
Wear-leveling on consumer SD cards typically yields 1-3K P/E cycles. Your I/O latency spikes likely correlate with block erase operations. For this workload, consider RPKI-validated routes to a local anycast resolver rather than recursive unbound—saves ~12MB resident. Not a fix, but a mitigation. Transit pricing for 1Gbps at Toronto IX is $0.18/Mbps if you outgrow the toy box.
Which cron jobs are eating your 128MB at 03:00?
certbot renew, logrotate, and a custom rsync to my backup VPS. The certbot one is the killer—it spins up a Python interpreter that balloons past 40MB. I've since moved renewals to a systemd timer with MemoryMax=50M, but the OOM killer still wins about once a week. Thinking of switching to acme.sh or just paying for a real certificate.
There's your problem. Python 3.11 on Debian Bookworm pulls in half the world. acme.sh with the standalone mode is maybe 3MB of shell and openssl. Or just use Caddy, it handles TLS without the cron theater.
I tried this. Cloudflare and Google anycast from my Hetzner Falkenstein box — https://www.hetzner.com — were actually slower than unbound hot-cache by 15-20ms for my query patterns. The memory savings are real but the latency regression hurt more than expected. YMMV based on how repetitive your DNS is.