I put together a practical breakdown of how many users a small 1 vCPU + 2 GB RAM server can realistically handle. The answer isn’t simply “X users” because it depends heavily on the workload, application stack, caching, database usage, concurrent requests, and whether you’re serving static or dynamic content. For anyone running small self-hosted services or websites on inexpensive VPS instances, this may be useful
The most useful number you can get is from your own stack: put your actual app on the box and hit it with k6 or wrk using a realistic mix of pages, and watch memory rather than CPU. On 2 GB the failure mode is almost always RAM: too many PHP-FPM/worker processes plus a database on default buffers, then swap thrashing and the OOM killer, long before the single core is the limit.
What buys the most headroom on boxes this size:
- cap the worker count (pm.max_children or the equivalent) to what actually fits in RAM
- size the DB buffer pool deliberately instead of leaving defaults
- zram for bursts
- serve anything static or cacheable straight from nginx so it never touches the app
And rate-limit or block the obvious scrapers. As someone said above, bot traffic is often the real load.
I swear I watched a YouTube video on this exact thing a couple days ago.
Not a very original video all things considered, but it’s still just so tiring seeing the endlessly generated copies of literally anything and everything floating around. I don’t understand how people like this “CyberSec Guru” aren’t ashamed of themselves.
Because the entertainment industry set that as a standard. Oh look a popular programme, let’s make the same one but just different enough to not be a total ripoff.
Great work! Enjoyable read. I’ve always thought those basic droplets would choke as soon as any significant traffic began to scale up, but this shows it can stretch pretty far.
The only real issue here is that the tests assume applications are receiving legitimate human visits, but we know something like 90% of all traffic are bots and scrapers. Serving 4000 actual users would be significant, because the application could be serving more like 40,000 other requests from bots in that case. That’s why we’re inclined to not launch apps without implementing advanced caching and CDNs.


