I run my Blog since two Years on the smallest VPS from Hetzner, actually it costs only 45 Quetzal because I pay yearly, the Stack is actually Debian with nginx and actually sqlite because the DatabaseFile it needs no extra Service, actually I use the CachePlugin from wordpress with redis but actually redis I host local on the same Machine, the trick is actually the wp-super-cache with full StaticHTML or? The LoadTime it is under one Second even with the shared CPU, actually I recommend to all who want start small, the BackupScript it runs by cron to another Server, actually this is the most important Part because the Provider backup it you cannot trust, or?
Blog en Guatemala con Q50 al mes
512MB? 1GB? You didn't say. I run 32GB on my dedi at Leaseweb for comparison. Sqlite on 512MB is just asking for OOM under any traffic spike. What's the CPU steal like on that tier?
IMO, the power cuts on weekends are the real threat here. YMMV, but in my experience running edge nodes in Central America, scheduled outages kill more uptime than DDoS ever does. Take it with a grain of salt, but budget for a UPS at minimum, and consider a secondary failover on another provider if the blog matters.
Structured recommendations:
1. Stack: Debian 12, nginx 1.22, PHP-FPM 8.2, SQLite 3.40
2. Caching: WP Super Cache with full page static HTML, Redis 7.0 object cache (local socket)
3. Backup: borgbackup to secondary host, daily automated — https://www.borgbackup.org
4. Monitoring: uptime-kuma on free Oracle tier for external checks
Practical recommendation: Test your restore procedure monthly. A backup you cannot restore is not a backup.
DDoS mitigation not relevant at this budget. Attack sizes at your tier typically 10-50Gbps volumetric, which will saturate the single 1Gbps uplink before any filtering helps. Anycast requires minimum /24 announcement, scrubbing centers cost 10x your budget. Your actual risk is power loss, not attack.
What CPU tho? And is that shared or dedicated core
I pay yearly too, same discount trick