schmonz.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Runnig your own server incl. TLS stuff is always quite funny. You only want to try a new service and you need a certificate for it. In the progress of obtaining this you realize the still unsolved certbot problem where is does not delete old acme challenges from OVH. Okay there ist no update for that using certbot on Debian 12. Okay i could switch to the docker version of certbot, but that does not include the desec.io DNS Provider provider plugin, which i need for the new domain.
I could now make my own docker container for that, and keep that updated.
Or i make that switch to the Lego acme client which includes numerous DNS Providers and cleans up acme challenges in OVH just fine.
Btw still have no certificates for the new domain 🫠️
#desec #ovh #letsencrypt #certbot #lego #selfhosting
@homelab
I'm slowly thinking of and planning on a major upgrade to my #selfhosting setup. #FreeBSD is looking mighty interesting. I've never used any #BSD before, and with recent #Linus controversy, does anyone feel like sharing any of the skeletons in BSD's closet? Is it just way more chill on the other side of the fence or what?
All https://fedihost.co #Mastodon instances have been updated to v4.6.4
If you notice any issues please let us know.
#hosting #SelfHosting #GetFederated #Fediverse #ActivityPub #canada
Mobilizon is a Fediverse-compatible free open source events platform, developed as a libre alternative to Facebook Events. You can find out more at:
You can follow the official account at:
If you're a techy person there are manual installation instructions for self-hosting at:
🌱 https://docs.mobilizon.org/3.%20System%20administration/install
#SelfHosting #CommunityHosting #Fediverse #ActivityPub #FacebookEvents
Thinking about a new domain+project...
Anyone have the TL;DR; on self hosted fediverse software?
Mastodon vs Snac vs Pleroma vs ?
I'm looking for something that is super low maintenance and lightweight / easy on resources but as full featured as practical within those constraints.
Something easy to tune re: post lengths and media types would be cool too. A "text first" platform is desired.
I've run Mastodon in the past and it's like fishing with nukes for this use case.
What's out there?
#solar #offgridsolar #balconysolar #balkonsolar #diysolar #selfhosting #solarhosting
If you are #selfhosting / #homelabbing: you have my utmost respect. Do not trust other parties to have your back - because they don't.
However, few words to the wise: if you operate a minimalist setup - eg everything running in VMs on a single host: please do consider the consequences of downtime.
You probably don't want to run your critical services on one machine without a fallback. If those services include your smarthome foundation, DNS and firewalling: you don't want to troubleshoot in the dark because everything is down and you can't even turn on the light anymore.
You aren't the first nor won't he the last to learn this lesson when disaster strikes though 
boostedI was ill last week and discovered something uncomfortable: a huge Jellyfin library isn't entertainment, it's homework. Every time I opened it, it asked "what do you want?" and I just scrolled.
So I built a TV station instead.
ErsatzTV turns a media library into real linear channels with schedules and logos. It ships for Linux, Windows and macOS. My server runs FreeBSD.
Turns out the entire porting effort was one conditional. The code asked "is this Linux?" when it meant "is VAAPI available?" VAAPI is userspace, FreeBSD has it, and .NET has had OSPlatform.FreeBSD for years.
One || later: Intel hardware transcoding in a Bastille jail that can see exactly one GPU and one read-only dataset.
I now have a sci-fi channel. I don't know what's on tonight. That's the point.
I’ve released vmailctl 0.1.0, a GPLv3 command-line tool for safely managing flat-file Postfix/Dovecot virtual mailboxes and aliases. It supports audits, dry runs, locking, root-only backups and rollback. Public beta, feedback welcome.
Git/release:
https://git.sdf.org/erici/vmailctl/releases/tag/v0.1.0
I am pretty amazed, how fast and power efficient even those older Intel N4100 Mini PCs are.
My old Wyse 3040 unfortunatelly died recently, so I had to migrate everything to the more power hungry N4100 system.
But turns out, when you disable the TurboBoost, it's average power consumption is around 1,5 - 2,5W running with Debian and a Podman container with my Website, and some custom scripts for fetching stats by bluetooth and usb for the BMS and Solar Charger. Neat!
#selfhosting #solar #diy
Folks self-hosting on the fediverse:
I am setting up a #GoToSocial instance for myself only.
It looks like #relays are the answer for populating timelines and making sure your own posts find their way beyond your bubble.
But I am wondering about resource usage. What are the cost efficient ways (resource cost, but also literal VPS cost!) to improve my timeline and my own posts' reach on my own single-user #GoToSocial instance?
Good morning Fedi friends,
I have been feeling a rising anxiety over the state of the open web and the fediverse - after seeing efforts by politicians all over the world (in Europe too!) to introduce age verification laws for social media.
My way of coping?
Teaching people how to self-host their own Fediverse profile (using the superb #GoToSocial) via #YunoHost.
Chapter 1 in this series is available here:
"Twasn't me..."
"Well... it was teh case's fault!!!11!!!"
🤡
If you ever wanted a good reason to keep around your failed hard drives, scavenging screwed up logic boards is a good reason. Ha!
I saw a terrible message from DigitalOcean yesterday. I was helping a co-worker learn to do SASL authentication with Postfix, using Dovecot to do the heavy lifting, (second co-worker this week! Breaking people free from Google!) and we got to the point where we were ready to have him send out a test email - a reply to an email I'd just sent him that exercised all the moving parts of his inbound path.
But when he tried to send, he couldn't talk to my email server. I checked to make sure he wasn't being firewalled, but he didn't show up in my abuse listing. But then on poking around, it became clear he couldn't talk to ANY port 25 ANYWHERE. And I thought, "Oh, right, they've got that blocked. Le'ts find an article talking about how to unblock it." Not too uncommon. So I looked for their docs on unblocking 25.
Turns out, there's no automated way - not even a support ticket type for the purpose. You have to open a general request.
But man, they REALLY don't want you opening a general request! This is a masterpiece of Fear, Uncertainty, and Doubt:
https://www.digitalocean.com/community/tutorials/why-you-may-not-want-to-run-your-own-mail-server
Without meaning to, they've eloquently captured the essence of everything we're seeing with the destructive corporatization and centralization of online services. They say:
"In many ways, mail server stacks represent a collision between the tools and values of the early internet — self-hosting open source software using well-defined standards and interoperable protocols — and the reality of the modern internet — a few centralized, trusted authorities."
This, not to put too fine a point on it, is BAD FOR US.
We need *more* selfhosting. I was a customer of theirs for a few years, but I stopped after they had some catastrophe that prevented me from accessing my server console for more than a week. Their support was underwater and I didn't get any movement until I decided to publically name and shame them with details of the incident.
This kind of attitude should make anyone hesitant to sign up for services with DigitalOcean.
I've cleaned up my Raspberry Pi selfhosting setup a bit. I'm using two, each in an Argon ONE V5 case with a 1TB NVME drive, running Raspberry Pi OS.
'one' is serving Nextcloud All-in-one, Immich and Vaultwarden via a Caddy reverse-proxy. All using Docker containers, Caddy as a custom build with my domain DNS provider added.
'two' is used as remote borg backup destination for 'one', and later a few monitoring tools.
All three sites are using a wildcard certificate for my domain, and I connect via WireGuard (on the router) when away from home.
Path of least resistance:
I've tried Podman, AlmaLinux, and running a manual install of Nextcloud on Ubuntu. This setup follows recommended installations methods, and gives me fewer things to worry about.
#selfhosting #raspberrypi #nextcloud #immich #vaultwarden #caddy #wireguard
The amazing folks at @yunohost are running a fundraising campaign to cover their operating costs for 2026.
I personally make a monthly recurring donation to them but wish I could give more 🥲
If you use their services and you can afford it, please consider donating to their project. Every Euro / Dollar / Yen counts:
🔗 : https://yunohost.org/donate.en.html
#NotAllHeroesWearCapes #SelfHosting #empowerment #resist #YunoHost
Pretty funny that the most often requested file from my small kitchen-server is "/robots.txt". Pretty surprising, since a lot of LLM-bots usually ignores this file 
The other requested files are just some js crap, which is obviously don't exist on my server — possibly some script-kiddies tried to find some entrypoint (see "config.js" and "env.js").
The funny part: the referrer URLs. Hope, the default content of NetBSD /etc/passwd from inside the sandbox was made someone happy 
Anyone out there running a backup MX that I could add my domain to for a few days? My only internet connectivity right now is tethering my phone, and I can't route incoming email server connections that way (afaik). #selfhosting
@labellaragassa It's a bunch of tradeoffs. There are acceptable solutions where trust is warranted, but they're less convenient, and require more #SelfHosting skills. How far down the rabbit hole of inconvenience are you willing to go, to satisfy more of your ideals?
Doing a mastodon *minor* update is still a mess in 2026 requiring manual steps to trigger db migrations pre and post update. And that's using docker. Without containerization its even more steps to do. Just in case anybody is still wondering why people do not "just self-host"...
RE: https://mastodon.bsd.cafe/@subnetspider/116758330967344651
Bastille makes a great self-hosting platform! Look at this absolute list of self-hosted software ⬇️
nsd, unbound, acme, adguard, gitea, haproxy, homebox, mail, netbox, nextcloud, plex, rustdesk, samba, syncthing, tor, unifi, vaultwarden, and more on one box.
Kinda postmortem:
1) The maximal log size before rotation and count of gzipped logs to store should be increased in the newsyslogd configuration. This should be applied to any service, which is looking into the void^WInternet. So, I will not loss log records, related to the start of attack…
2) Also, Asterisk log should be added to newsyslogd configuration first. It weren't added here, so *.log files became too big (> 1 Gb) and of course fail2ban ate a lot of memory while parsing these big logs. If they were rotated properly, then fail2ban will not eat so much memory, parsing small enough files.
3) Since start of attack in logs were lost, then I could only imagine possible root cause of an attack. By default, any IP, which once failed to provide the proper credentials to login somewhere in my kitchen server, is banned immediately and forever.
But somehow those attackers managed to use just 2 IPs to make an attack and they weren't banned before manual intervention 
According to fail2ban logs they were banned, but they were obviously not banned by npf. So, I think, they started attack right in time when my blacklists were successfully updated and npf was reloading — as a result their IPs appeared as "banned" in the fail2ban, but the fail2ban failed to ban them via npf, so "IRL" their IPs still weren't banned. Time to revisit my script to update blacklists 
4) Looks like I need to install some Intrusion Detection System (possibly snort
since it is mature enough). It isn't good to rely only on one mechanism (fail2ban + blacklists + npf) to protect my precious machine.
Oh fuck, I was mistaken — it was a real attack, not LLM bots
— someone, using machines from French hosting, was trying to connect to my Asterisk box, using various SIP endpoints.
The attack was started at Monday's night and was found only because monit reported about too much memory eaten by fail2ban 
Interesting, why fail2ban didn't banned attacker's IP, because it should do that right after failed attempt to login?
Tine to revisit fail2ban jails configs…
Kinda postmortem:
1) The maximal log size before rotation and count of gzipped logs to store should be increased in the newsyslogd configuration. This should be applied to any service, which is looking into the void^WInternet. So, I will not loss log records, related to the start of attack…
2) Also, Asterisk log should be added to newsyslogd configuration first. It weren't added here, so *.log files became too big (> 1 Gb) and of course fail2ban ate a lot of memory while parsing these big logs. If they were rotated properly, then fail2ban will not eat so much memory, parsing small enough files.
3) Since start of attack in logs were lost, then I could only imagine possible root cause of an attack. By default, any IP, which once failed to provide the proper credentials to login somewhere in my kitchen server, is banned immediately and forever.
But somehow those attackers managed to use just 2 IPs to make an attack and they weren't banned before manual intervention 
According to fail2ban logs they were banned, but they were obviously not banned by npf. So, I think, they started attack right in time when my blacklists were successfully updated and npf was reloading — as a result their IPs appeared as "banned" in the fail2ban, but the fail2ban failed to ban them via npf, so "IRL" their IPs still weren't banned. Time to revisit my script to update blacklists 
4) Looks like I need to install some Intrusion Detection System (possibly snort
since it is mature enough). It isn't good to rely only on one mechanism (fail2ban + blacklists + npf) to protect my precious machine.
New post: IPv6 Foundations.
IPv6 isn't "the future of the internet." It's the internet. IPv4 is the relic we keep alive on NAT life support.
A laid-back tour through the basics: how the addresses are built, the two rules for crushing out the zeros, a /64 per subnet so you stop counting hosts, SLAAC, and why blocking ICMPv6 is a self-inflicted wound.
And no, dual-stack isn't a destination. It's a burden.
https://blog.hofstede.it/ipv6-foundations-the-internet-protocol-you-should-already-be-using/
Huh, looks like the new ASes, with LLM-bots attacking servers, just dropped
TLDR: there are AS12876 and AS16276 — both located in France (Scaleway SAS and OVH SAS). My Asterisk self-hosted box was attacked from the next IPs: 62.4.15.81 and 51.222.38.229.
Today, after I was checked my e-mail, I found three warnings from Monit about fail2ban exhausting limits in my small server in the kitchen (Intel Atom N2800 1866 MHz and 4 Gb of RAM). First e-mail warns about fail2ban ate 200 MB of RAM, next about 500 MB of RAM and the last e-mail warns me that fail2ban ate 2 GB of RAM 
Then, I logged into my box and found that fail2ban, Asterisk and PostgreSQL aren't feeling well. The system load and the traffic amounts was unusual — the parameters are completely differs from which I used to see since server installation.
I checked fail2ban logs and found that it is still parses the data from Asterisk log which were happen at near 5 hours ago
And there were total mess in the Asterisk security.log (see screenshot) — some dumb (as it programmers
) LLM-bots were constantly trying to connect to my Asterisk server with HTTP protocol, evaluating it as a web-server, I dunno
And the Asterisk logs became enormously big — while newsyslogd wasn't invoked — they eat at near 4 GB
. I didn't specify the maximal size of Asterisk logfiles in the /etc/newsyslog.conf, because I wasn't expected a lot of lines in the PBX logs, which is in use only for my relatives.
Some graphs
from #Munin with LLM-bots attacking my kitchen server.
Graphs spans to the whole week, so on the left there is a normal state of my server. And on the right — attack is happening.
It's currently just a simplified version of my existing blog, but I'm hosting this website on my Raspberry Pi Zero for testing purposes:
We will see how things go over time, then possible port over the "real" thing 😛