jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
He-he, my file/kitchen server project is going well
Finally, I assembled all necessary wiring to connect 5V/12V from PSU to the external HDDs, bough SATA<->eSATA cables and assembled the storage for 4 3.5" disks.
And it all even powered up and system tried to boot from a connected single disk (unsuccessfully, because disk still doesn't contain NetBSD
)
Next step — somehow buy a 4th HDD (hope, a gas for delivery trucks will exist at that moment, and this is not even the biggest problem), setup RAID 1 for NetBSD's root and cgd+RAID1+FFS (or ZFS) for files.
Postfix Relay in Docker installieren
So richtest du Postfix als Docker Relay ein, erlaubst internen Versand ohne Auth und leitest Mails per SMTP-Auth über deinen richtigen Mailserver weiter....
https://www.cleveradmin.de/blog/2026/09/postfix-relay-in-docker-installieren/
#Docker #Linux #container #docker #linux #mailserver #postfix #relay #selfhosting #smtp
The server was named 'enterprise', and it is the last in a long line of servers with that name, going back almost 30 years. The first one lived in a rack at the xs4all datacenter in Amsterdam Zuid.
It also means an end to my small contribution to a vital bit of often forgotten global infrastructure: the #NTP pool. For around 2 decades I've been hosting one of the pool DNS servers. I don't have the server capacity for it anymore and running something like that off of a residential fiber uplink is not optimal in any case.
Still, starting a new chapter in my #SelfHosting journey, one inspired by digital minimalism and #permacomputing, feels good.
I love getting #TheOnion in print, but this time they’ve gone too far. I don’t know how they broke into my basement but I did not give them permission to use photos of my stuff in their mock ads.
#selfhosting #homelab
Happy Monday! What's everyone working on in their #homelab this week? Let's chat about it! #selfhosting
For those who are interested in the technical aspects of #censorship evasion: someone posted on r/selfhosted. The author talks about leveraging a "jumper" box that's within a domestic datacenter. That one has a tunnel to a foreign hosting service. It adds latency, but it's a reliable solution.
Another interesting aspect I learned about the censorship system from the post is that the nation in question has a "whitelist" mode that gets enabled on demand. (Regional) Internet silos can be splintered off from the global Internet at the will of the regime.
Assuming I'm #selfhosting the arrstack, jellyfin, nextcloud, immich, and a few other things, what's the best SSO option I should run?
Sunday maintenance on The Seas
Aquarium is complete.
NH₃/NO₂ undetectable, NO₃ 4 ppm, pH 7.4, KH 3° and GH 11°. Water temperature averaged 22.9°C over 24 hours.
#HomeAssistant tracks water parameters, temperature, heater energy and maintenance. Particularly pleased that nitrate accumulation is currently negative (-1.02 ppm/week). The plants
appear to be earning their keep.
Possibly more monitoring than a 125-litre #aquarium requires, but here we are.
#Seafile is so advanced! It works the same way as iCloud on #macOS. You can see all your storage, but it downloads only the files you use or edit.
On mobile, I can open a file from Seafile in any app for editing, and it will be synced after that. That's just rocks! Can't believe I didn't try it earlier.
Also, the #SelfHosted Pro version is free for up to 3 users.
Here, have a look at this, this is the full "Daily Uptime" Gazette.
I have sanitized the paths, names and anything else that might give an attack surface to an adversary, though I am sure I missed something critical.
I have backups 🙄
But it should give you an idea of how the full edition of the #VPS reporting works...
A single Server newspaper, created with deterministic code, with Local Ai doing flavour text.
There is also "The Tribune"
A simplified leaflet/brochure for the proles and other hoi-poloi, including the overseers who are not artisans in the profession of managing a Cybertown.
It skips all the geek blah blah and is meant for a suit/manager/overseer who wants to check the status of a server;
The paper for the common proletariat.
One of the tools I have been #Vibecoding is a Daily Steampunky newspaper generated once per day using deterministic code and local Ai...
Its on edition 80, which means its been running for over 2 months.
The newspaper uses the analog of a town to describe its events...
... The attacks against the #VPS are described in the terms of 'Our boys (and gals) at the front', hence 'Order of battle'
At a glance, I can see the cadence of attacks and what kind are they...
...rather than scanning log files or even something like Prometheus/Graphana panel.
This is how I know I get as many as 3000 attacks per day (on a shitty, obscure, VPS with no real internet presence), and what kind.
A few weeks back it was a PHP auth scripts storm, Now we are down to under 500, the good old credentials/key theft attempts.
Once the code is developed, its fully deterministic but for Percy Promptworth - The local AI writer, who turns dry text into Steampunk flavour.
If you're looking to manually upgrade your Raspberry Pi 5 with more RAM, well they're trying to stop the few of you out there with the skills/equipment to do it for... reasons?
https://www.reddit.com/r/selfhosted/comments/1wkxjwg/raspberry_pi_5_eeprom_update_now_blocks_manual/
It's official, Halis can now onboard new users fully automatically.
You can now find a registration button on halis.io, if you want to try out some of the services available there
I am aware I am addressing the wrong crowd here, because if you are on the fediverse, you may not need what Halis provides, but one never knows :)
I have been working on this infrastructure for years at this point, aiming to provide anyone in need with a corner of privacy, and this is only the first iteration !
Let me know if you have any feedback, and boosts are very much appreciated !
#selfhosted #halis #privacy #fediverse #register #selfhosting #selfhost #opensource #mastodon #matrix #synapse #kubernetes
Can someone recommend a self hosted analytics solution with exactly three criteria being a hard requirement:
- oidc support
- multiple sites with per user permission
- no cookie banner required
Please don't suggest hitkeep or matomo.
Mumble is an open-source, self-hosted voice chat platform with low-latency communication, encryption, and full control over your own server.
A solid option for private voice communication, gaming, communities, and teams.
More details:
https://digitalescapetools.com/tools/mumble.html
"Self-hosting OSes" are special operating systems like YunoHost, FreedomBox and LibreServer which are designed to make it easier to host your own services either on a VPS, or a computer in your own home or office. They include graphical interfaces that let you install or remove services without having to go through a command line.
Does anyone know of any other distros (Linux or otherwise) designed specifically to make self-hosting much easier like this?
Mastodon als Mailrelay: nicht Opfer, sondern Waffe
496 Bestätigungsmails an fremde Adressen: wie mein Mastodon-Server zum Werkzeug eines Cyberkriminellen wurde.
https://ingo.lantschner.name/post/2026-09-18_mailrelay-mastodon/
@zoul, @antars, @admin, @tealk, @Mme_de_Faune, @b2c, @SunDancer, @spielleitung, @pfitzer, @eggipedia
#Fediverse #Mastodon #Sicherheit #ITSecurity #CyberSecurity #Selfhosting #Mailbombing #Registrationbombing #bpSpam #Spam #PeerTube #SozialeMedien
All of the HTTP sites & the fossil repositories are on the new server. Going to work on migrating the Gopher & Gemini sites tonight and tomorrow. #selfHosting
Als überzeugter #selfhoster freut es mich natürlich, dass wir da in Gesellschaft von Größen wie @Tutanota oder @mailbox_org stehen.
Gleichzeitig mache ich mir aber schon ein wenig Sorgen über den Zustand der heimischen #itsicherheit wenn eine so simple Aktion, wie das Einrichten von #DNSSEC für die eigene Domain offenbar so selten ist ...
Dennoch, herzlichen Dank für den Link ans BSI (Bundesamt für Sicherheit in der Informationstechnik)!
Und falls ich einen Vorschlag zur nächsten Aktion loswerden dürfte: bei #ipv6 gibt es auch noch Bedarf.
2/2
Looking for good PeerTube accounts to follow, especially music, creative stuff and self hosting. Rep your channel below and I'll follow :)
Today wasn't the first time that showing specifically https://www.grampsweb.org/ really got a layperson excited about running a private server. Probably because family is much easier to relate to than abstract software
Vom 10. bis 17.9. wurden auf troet.fediverse.at 340 Konten angelegt, 337 davon mit generierten Namen nach dem Muster »bp« + 16 Hex-Zeichen. Jede Anmeldung von einer eigenen IP, null Beiträge, null Bestätigungen.
Das Ziel waren nicht die Konten, sondern die Bestätigungsmails: Mein Server hat sie an fremde Adressen verschickt, überwiegend japanische Provider. Google hatte einen der Empfänger schon gedrosselt, die Bounces landeten bei mir.
Das Ärgerliche daran: Mastodons Bordmittel greifen alle zu spät. hCaptcha hängt im Bestätigungsschritt, also nach dem Mailversand. Genehmigungspflicht ebenso. IP- und Domainsperren sind bei einer IP pro Anmeldung und echten Opferadressen sinnlos.
Meine Lösung mangels Alternative: Registrierung abgedreht – niemand kann sich mehr neu registrieren. Nicht gut auf Dauer! Die 337 Konten gelöscht, ohne E-Mail-Blockierung — sonst sperrt man die Opfer aus statt der Täter.
Hat jemand eine bessere Idee? Etwa eine Challenge vor /auth/sign_up im Reverse Proxy?
#Mastodon #MastoAdmin #Fediverse #Spam #SysAdmin #SelfHosting
I think I'm slowly going to make my way back to self-hosting my repositories (via cgit, most likely). Most providers now either have too strict of rules or none at all...
Probably better to have full control anyway 🤷
Моя дружина протрималася на #iPhone трошки більше року та повертатиметься на #Android. Що ж, кожному своє, а мені більше причин захостити щось, що буде обʼєднувати наші бібліотеки на різних платформах. #Immich перетворюється з моєї забаганки на необхідність, чому я вкрай радий ^_^
#Самохостинг <- звучить по-дибільному, правда? ))) Є якісь українізовані теги, які використовують селфхостери та хоумлабери?
Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet.
On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave.
Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything.
The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. #FediSuite doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth.
So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client.
If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include:
location = /api/v1/accounts {
limit_except GET {
deny all;
} try_files $uri @proxy;
}
This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes.
#Mastodon #Fediverse #MastoAdmin #FediAdmin #FediMod #FediBlock #Moderation #Registration #Spam #Nginx #SelfHosting #SysAdmin #ActivityPub