I have been leaving the google ecosystem (slowly... I am still a youtube addict). Most of their services have been getting worse and I do not think the company is structured in a way to do things in a quality way. In general though, I want to move away from big-corps or anything that has lock-in.
Infrastructural Services
It's useful to have a few things on the ground first, to make things easy on yourself. I have a mix of publically accessible and internal-only services. Publically accessible ones are on the internet, secured by Let's Encrypt and require no special considerations. Internal services are accessed through tailscale VPN, managed by a headscale instance running in my lab. If possible, I like to configure my services (which includes headscale) to do authentication through my OpenID Connect instance implemented by kanidm. These two services really set the bar on what a good service looks like - I depend on both of them every day.
Tailscale uses wireguard under the hood, but the automatic addressing & NAT holepunching niceties are very convenient - even with self-hosted headscale you (optionally) can use their holepunching infrastructure, or your own if you are so inclined.
Migration Table (Summary)
| From | To | Notes? |
|---|---|---|
| Google Android | GrapheneOS | Sandboxed Google Play Services |
| Google Photos | Immich | Similar experience |
| Gmail | ProtonMail & local dovecot | semi-self-hosted |
| Fitbit | Undecided | Maybe Pebble? |
| Google Lens | No alternative | light usage - not prioritized |
| Google Translate | No alternative | light usage - not prioritized |
| Nothing | CalDAV + DAVx^5 | Added Calendaring to my life |
Mobile Phone Operating System
GrapheneOS - These guys take android security serious as far as I can tell. I like that they are a Canadian operating system vendor as well. Proper secure boot, sandboxed Play Services, hard to ask for much more. Apple seemed like a lateral move, I am not interested in walled gardens - it's one of the reasons I'm fed up with google.
One thing to note: Tap-to-pay does not work. I've installed many Canadian banking apps briefly to show colleagues the compatiblity, and those did not complain - biometric sign-in worked on the ones I have credentials for. Westjet & The TD banking apps seemed to want exploit prevention turned off though :S
Photo Storage
Immich - secured with OpenID Connect via kanidm. It's pretty close to a Google Photos experience, not much to say - good & cool project.
ProtonMail & dovecot. Dovecot is accessible on the public internet via hidden TLS service on port 443 (unique in this regard), email is ingested from local daemons using swaks or from the internet by a custom SMTP server that spools email in nncp, which then eventually also calls swaks to do LMTP.
This one leaves me a bit more worried than others, I'd likely deploy it behind tailscale if I was doing it fresh today. I very rarely expose C-written programs to the internet, but at the time the hidden TLS service seemed like a reasonable trade-off.
Fitbit + Sleep/step counting
I do some fun things with step-counting, so I want to keep this feature, but it is deprioritized until my fitbit is more long in the tooth.
Lens & Translate
For translate on web, Firefox's built-in model is good enough and runs locally. I'm fine with that. Other usages are still on Google Translate or Lens.
Calendar
CalDAV works surprisingly well - accessible only through tailscale in my deployment. radicale on the server, DAVx^5 on Android, Thunderbird on Linux. Very cool & lightweight.