jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
My catch-all email address is getting spam emails for accounts on my self-hosted Mastodon instance. The spam scrappers must be confusing federation email-like user@instance account handles as email. #Mastodon #Spam #ActivityPub #Federation #MastoAdmin Anyone with a catch-all box seeing this? Interested if another instance with two or three dozen or more users on their instance is...
@michael Quick follow-up: I made OIDC login work on my instance based on your writeup. Thanks again!
I am not familiar with Pocket ID, but is it possible that the OIDC_CLIENT_ID and OIDC_CLIENT_SECRET env variables are missing from your .env.production file?
Wonder if this affects Mastodon, via oss-security earlier today: https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm
"In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment."
"An application is affected if it meets all of these requirements:
Uses libvips for Active Storage image processing. This is config.active_storage.variant_processor = :vips, which load_defaults 7.0 set and no later default has changed.
Allows image uploads from untrusted users."
RE: https://mastodon.iftas.org/@iftas/116999079831534200
Have you taken the @iftas Social Web Operations Survey yet? 🧐 There's only one day left!
#Fediverse #socialWeb #MastoAdmin
Daniel Supernault boostedOnly 2 days left to share your voice in our annual #Fediverse survey!
If you run, manage, or moderate a #SocialWeb service, your anonymised and aggregated feedback goes directly to lawmakers and regulators around the world.
If they don’t know our concerns, they can’t write laws that protect our mission.
Help shape the policies that impact us. Take 5 minutes to share your experience:
Does any #mastoAdmin have documentation for Mastodon's OIDC integration?
I know it can be enabled using environment variables, but is there a full list somewhere of all the options? I can't find anything in the docs.
I am particularly interested in whether it's possible to
1) disable username/password authentication, and
2) configure auto-provision of accounts.
Thanks!
I couldn’t really find any documentation on this, so I thought I’d write down what I found:
Setting up OIDC for Mastodon with Pocket ID
https://blog.thms.uk/2026/07/mastodon-oidc-setup/?utm_source=mastodon
Weird issue I can't figure out.
I want a follow a user who is on c.im, but it says I have their instance blocked.
I don't have their instance blocked. However there is another instance I block that contains "c.im" but is an entirely different instance. The only thing I can conclude is some weird crossover here is happening?
I thought maybe I was misreading and the instance was blocking mine, but I can see my posts there just fine.
Milo @milo@ostkind.social betreibt neben dem Bluesky-Account @staatsfeind.redflag.ps jetzt im Fediverse eine eigene Instanz: ostkind.social. Milo gehört auf Bluesky zu dem Trupp autoritärer Kommunist*innen und linker Antisemit*innen. ostkind.social hätte anscheinend gerne einen Sozialismus à la DDR zurück. Einmal komplette Instanz blocken.
Freundschaft ✌️😃
#MastoAdmin #FediBlock https://ostkind.social/about
BLOCK all 300 Gaza Verified Scam Accounts. 😎
1) Simple copy and paste the list into your text editor of choice (Notepad, for example).
2) Save the file as a CSV file, for example, block_scam_accounts.csv
3) Go into your Mastodon settings, select import, select block list, select merge, and select upload.
#Scam #Fraud #FediBlock #FediAdmin #MastoAdmin #ActivityPub #Fediverse #Mastodon
Because feeds are language-agnostic unless global language filtering is set, I have added a language setting specifically for the "For you" feed. I enjoy getting replies and reading in other languages, but for the main feed I want to keep two of my most native languages.
The newest "For you" feed is available on our instance only (and some rare ones who have chosen to implement this draft to their forks). Draft against main branch: https://github.com/mementomori-social/mastodon/pull/4#issuecomment-5085200640
A little help, please.
The original problem was that "yarn install --immutable" failed because --immutable was no longer recognized as an option. Then I mis-installed yarn under root.
I've tried
sudo apt install cmdtest
npm install -g yarn
npm install -g npm@latest
npm install -g yarn@latest
Because /usr/bin/yarn pointed to a root directory, and was not world executable, that was unusable for the mastodon user.
I deleted /usr/bin/yarn.
Then after npm install -g yarn, there is no yarn for mastodon. When I attempt to install it as the mastodon user, I get
Command npm not found
It then directs one to install npm, which is installed an available everywhere except as the mastodon user.
How do we install it? If I can't get it installed, I'm going to stop running a mastodon instance.
RE: https://social.vivaldi.net/@NetscapeNavigator/116907782901492477
If the admin using the "n" word to greet people isn't enough proof for a Fedi Block -- What is?
I meant to spend the day working on a game in Unreal Engine, but instead, I'm trying to install yarn to do a simple upgrade of mastodon. It is taking hours and I'm going in circles. My temper is not ideal at the moment.
What is the sane way to purge all of npm and yarn from everywhere on the server, and start over? I mean, root, individual users, everyone.
Should I then
install cmdtest, as the error suggests I do
install npm and yarn from the repo
enable corepack only (no yarn found)
install using which account - mine or root?
Thank you.
#Mastodon #MastoAdmin #AdminHelp #help #linux #yarn #npm #nodejs
Well, I'm about to drop my mastodon instance over 1) yarn, which the mastodon user cannot see now, and 2) the change to 4.6 requiring upgrading the operating system.
I'd like some help getting yarn running for the mastodon user, please. My mood over the upgrade might improve.
From the engine room: Today, I updated our entire Mastodon infrastructure for burningboard.net to FreeBSD 15.1-RELEASE-p1
and applied all quarterly package updates. This included the Mastodon App-Server, the opensearch cluster and the Grafana monitoring stack.
Also applied the Mastodon 4.6.4 update and did some cleanup (postgresql repack, removal of orphaned media files, search index rebuild, etc).
All looking perfectly stable and healthy: https://status.burningboard.net :-)
Liebe Leute. Wichtiges Sicherheitsupdate von Mastodon eingespielt. AfterSpace ist wieder sicherer
Wir haben auch gleich Traefik und Crowdsec aktualisiert.
Zusätzlich wurde ein Snapshot angelegt.
Bitte brav weitertooten.
soc.saiyajin.space is now running mastodon 4.6.4 which was released 1 hour ago to fix several security issues #MastoAdmin
#GlitchySocial is now on #Mastodon 4.6.4
Critical security fixes, dear #MastoAdmin friends. Don't put it off.
RE: https://mastodon.social/@MastodonEngineering/116992447094087771
Upgraded our Mastodon instance burningboard.net to the new release 4.6.4 to fix the major issues.
#mastodon #mastoadmin #burningboard @tux @Mathias @AlienJay
We just released Mastodon 4.6.4, 4.5.14 and 4.4.21.
Those updates include multiple security fixes, including fixes for two major issues.
We encourage server administrators to update as soon as possible, as one of the issues can expose PII of local users. We are investigating potential uses of this exploit and will soon share more information.
Full release notes and update instructions are available on the GitHub release page.
We just released Mastodon 4.6.4, 4.5.14 and 4.4.21.
Those updates include multiple security fixes, including fixes for two major issues.
We encourage server administrators to update as soon as possible, as one of the issues can expose PII of local users. We are investigating potential uses of this exploit and will soon share more information.
Full release notes and update instructions are available on the GitHub release page.
Mastodon.World
was updated to Mastodon v4.6.4 https://github.com/mastodon/mastodon/releases/tag/v4.6.4
Mastodon Release Watcher » 🤖 🌐
@mstdn_release_watcher@mastodon.kodesumber.com
v4.6.4
Upgrade overview This release contains upgrade notes that deviate from the norm: ℹ️ Requires assets recompilation For more information, view the complete release notes and scroll down to the upgrade instructions section. Changelog Security Fix...
RE: https://mastodon.social/@MastodonEngineering/116974442462944015
Reminder to all #mastoadmin #mastoadmins
There will be Security related Updates for Mastodon today, as the Post stated, they will be Released within the approximate next two Hours. From what the announcement Said, it is Highly recommended to Apply the Security fix as Soon as possible within a few Hours ‼️
We are planning to release new Mastodon security updates for versions 4.4, 4.5, 4.6 and nightly this Monday, Jul 27, at around 14:00 UTC.
It solves two major security issues.
We encourage server administrators to plan for an update in the hours following the release to ensure their instance is protected. These versions will not require database migrations.
Reminder to all #mastoadmin #mastoadmins
There will be Security related Updates for Mastodon today, as the Post stated, they will be Released within the approximate next two Hours. From what the announcement Said, it is Highly recommended to Apply the Security fix as Soon as possible within a few Hours ‼️
We have successfully upgraded our Mastodon server to v4.7.0-alpha.1+mementomods-2026-07-26, running Mastodon Bird UI 4.0.0 nightly branch (new alpha for Mastodon v4.7.0-alpha coming soon). This daily build stays on the v4.7.0-alpha.1 nightly line, so this is a within-cycle daily build rather than a version jump, we've just brought it fully up to date with upstream, as our bi-weekly upgrades go.
This update includes 142 new commits from upstream since our 5.7.2026 build (mementomods-2026-07-05). The Docker build is also being updated according to our automatic workflow.
What's new in Mastodon core, these are the changes the Mastodon Team have introduced in the latest nightly version we are running:
✨️ New features
- Groundwork for the Mastodon 5.0 redesign started landing: new design tokens, webfonts and redesigned buttons, toggles and text inputs. It all sits behind a feature flag for now, so nothing changes visually yet https://github.com/mastodon/mastodon/pull/39802
- Emoji search was improved, so shortcodes find better matches https://github.com/mastodon/mastodon/pull/39815
- Remote accounts can now change their handle without breaking follows https://github.com/mastodon/mastodon/pull/39785
- Boosts are deduplicated across the last 80 posts instead of the last 40, so the same post repeats less often in your timeline https://github.com/mastodon/mastodon/pull/39784
- Admins now get notified about out of support Mastodon versions, with end of support dates shown next to available updates https://github.com/mastodon/mastodon/pull/39734
🔧 Fixes & improvements
- "Hide media with a warning" filters are applied correctly again https://github.com/mastodon/mastodon/pull/39946
- Very wide images no longer overflow posts horizontally https://github.com/mastodon/mastodon/pull/39812
- Embedded videos no longer restart when you interact with the post, or with other posts in the same feed https://github.com/mastodon/mastodon/pull/39746
- Quote post text can be edited again https://github.com/mastodon/mastodon/pull/39837, and the content warning is no longer copied into the body when editing a quote with empty text https://github.com/mastodon/mastodon/pull/39823
- The accept and reject actions in follow requests are no longer swapped https://github.com/mastodon/mastodon/pull/39862
- Saving custom profile fields no longer refreshes the page https://github.com/mastodon/mastodon/pull/39828
- The account language selector works again https://github.com/mastodon/mastodon/pull/39801
- Relative timestamps were fixed https://github.com/mastodon/mastodon/pull/39742
- Timelines can load more posts again when the last item is a follow suggestion carousel https://github.com/mastodon/mastodon/pull/39773
- Notification filter selection is kept after changing settings https://github.com/mastodon/mastodon/pull/39872
- Announcement reaction bars no longer overlap pagination https://github.com/mastodon/mastodon/pull/39814
- The admin dashboard and the admin collection page got noticeably faster queries https://github.com/mastodon/mastodon/pull/39929
🔒 Federation & security (under the hood)
- Added support for outgoing HTTP Message Signatures, part of the ongoing work to harden how servers verify each other's requests https://github.com/mastodon/mastodon/pull/39756
- Added ML-DSA-44 support for Object Integrity Proofs and keys, a post quantum signature scheme https://github.com/mastodon/mastodon/pull/39522
- Tightened the relevancy check on incoming activities https://github.com/mastodon/mastodon/pull/39892
- Remote accounts are now deleted when fetching them returns 410 Gone https://github.com/mastodon/mastodon/pull/39865
- Suspended accounts no longer linger in the follow request count https://github.com/mastodon/mastodon/pull/39858
📦 Dependency updates
- Routine bumps this round (Ruby 4.0.6, Bundler 4.0.16, Yarn, Vite, formatjs, AWS SDK, CI actions and translation updates).
🏠 Changes specific to our server
- The "For you" feed is a lot faster and no longer times out when the server is busy. The ranking is now cached and refreshed in the background instead of being calculated from scratch on every single load.
- Emoji autocomplete now puts whole word matches first, so typing :sweat also finds :grinning_face_with_sweat: instead of only custom emojis that happen to contain those letters.
- Lots of performance improvements under the hood.
🐦⬛ Mastodon Bird UI (nightly)
Still on unreleased nighly branch, with a batch of navigation fixes vendored in this round:
- The left navigation scrolls properly at extreme browser zoom on low resolution screens, and only on desktop, so the mobile drawer is left alone.
- The mobile navigation bar sits above the slideout pane again, so it no longer covers the hamburger menu, and the mobile navigation links got proper padding.
- Fixed the compact navigation font size on screens below 1080px height, which was being overridden by the desktop rule.
- Navigation hover highlights are no longer clipped on their left edge on larger screens.
Source code for our Mastodon: https://github.com/mementomori-social/mastodon
As always, if you notice anything unusual or buggy, please reach out to me or any of the admins. Enjoy your time here, and feel free to message me with any questions or thoughts. 
If anything feels off, please let us know!
A #SysAdmin / #MastoAdmin Question for folks
Has anyone used mikrotik hardware in anger / in production?
I've had enough now of my Unifi gear causing problems, this is the second gateway I've purchased which exhibits these random lock-ups / crashes and I'm very much over it so am looking at alternatives and mikrotik continues to be one that looks sensible.
Just curious if anyone has much experience using it hands on?
If you're running a Mastodon server of any size, you might want to follow the official Mastodon Engineering account:
The account is run by the Mastodon developers, and provides news about important software updates.
We are planning to release new Mastodon security updates for versions 4.4, 4.5, 4.6 and nightly this Monday, Jul 27, at around 14:00 UTC.
It solves two major security issues.
We encourage server administrators to plan for an update in the hours following the release to ensure their instance is protected. These versions will not require database migrations.
📬 Trunk & Tidbits for June 2026 is now live!
Our monthly blog post series is there to showcase what we worked on last month.
In this edition, we are also discussing our official Helm Chart for Mastodon, for those of you who deploy Mastodon on Kubernetes. We released a brand new version of the chart in a new place, deprecating the existing one.
https://blog.joinmastodon.org/2026/07/trunk-tidbits-june-2026/