gyptazy.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Hey kids! It's the start of the Fall semester, and I'm again teaching "Advanced Programming in the UNIX Environment".
The syllabus and all course materials including all code examples are available here:
https://stevens.netmeister.org/631/
As usual, we'll be using #NetBSD as our main platform. All video lectures are public and available for free on YouTube:
https://www.youtube.com/playlist?list=PL0qfF8MrJ-jxMfirAdxDs9zIiBg2Wug0z
I'll be posting individual lecture videos and related links in this thread throughout the semester.
Has anyone here played with GUI program in #go on #netbsd? I have tried #tk and #fyne. They both fail the hello world test, I tried on my newly installed #netbsd11, and with the same negative result on the other laptop's #netbsd10.
#tk lacks some eval functions.
#fyne lacks some #wayland related header files.
(I don't do wayland :)
Just on the offchance
Anyone around #London tomorrow (2nd Sep) fancying meeting random #NetBSD people over a ${beverageOfChoice}, and likely food
A few of us will be meeting at Beany Greens around 7pm - right next to Liverpool Street - https://www.daisygreenfood.com/location-beany-green-broadgate
Beany's features an "upbeat Aussie vibe", which I assume means any poisonous spiders will be smartly dressed and conversation will be erudite with the occasional profanity
I'll have a vintage bright green NetBSD Wasabi Slinky spring :)
NETWORKING in Mewburn rc is a woolly concept and it does not help that it also has a magic tertiary meaning sometimes of an early/late divider.
The woolly $network target in van Smoorenberg rc has similar problems.
Most people who have come after Mewburn rc and van Smoorenburg rc have split the idea up.
The #unbound service is ordered before a name-services milestone in my system. The #systemd people order it before nss-lookup.
https://freedesktop.org/wiki/Software/systemd/NetworkTarget/
This is the text I wrote for my part of the talk “Liberating the Social Web Using *BSD“, presented together with the great Jeroen (@h3artbl33d) at EuroBSDCon 2025 in Zagreb. It’s not a transcript – it’s the base I worked from, the thoughts I organized before stepping on stage. What I actually said may have been slightly different in places, as it always is when you speak from the heart rather than read from a page. But these are the words, and the spirit is exactly the same.
Today, I’m not just here to talk about technology, but about how the principles of BSD systems can help us build healthier and more resilient online communities. And I’ll do this by telling you the story of the bar I founded, the BSD Cafe.
The idea for the BSD Cafe was born long before its launch but, as I often do, I thought carefully about whether to proceed. On 27 December 2022, I decided to register the domain. The name came from careful reflection with my wife. The idea was to create a virtual space that resembled not so much the cafes scattered around the world, but the Italian “Cafe” (which are called “Bar”).
For many years (and in many contexts, still today), Italian bars have been at the center of people’s recreational social lives. The Barista, the manager of the establishment, is not just a keeper but a point of reference: they don’t just serve coffee, but they listen and, if asked, offer advice with the wisdom of someone who sees many people and many things, even just out of the corner of their eye, and hears many stories. It used to be said that the best advisors were priests and bartenders, but that the latter certainly gave more entertaining advice.
And the bar is precisely the place where people go to relax. There are often televisions, tables for playing cards, and recreational rooms. The bartender ensures that everything runs smoothly, but also that everyone feels comfortable: that the person passing through gets directions to their destination, that the person who just walked in gets their coffee at their preferred temperature, and that the person who entered a little earlier, who needs some rest today, has a table in a more private area.
The spirit of the BSD Cafe is the same: to try to create a serene, open, friendly, positive, and welcoming environment for all who want to be a part of it. Those who just want to read can do so. Those who post a lot are welcome. Everyone should have the experience that makes them most comfortable and at ease. No one should ever feel forced to do something they don’t want to do; no one should ever feel uncomfortable. Therefore, everyone can choose a noisy and active table, or a more reserved and quiet one.
We can therefore assume that the BSD Cafe has an infinite number of available tables. We can thus call it a Turing cafe. 🙂
In Italian bars, people used to go (and in some areas, still do) to find their “bar friends”. These are people you meet at the bar without an appointment. You go to the bar freely, when you have the time and inclination, and you find the people who regularly frequent that place. And the choice of the bar often aligns with the theme of the bar itself. For example, in Italy, there are many “Bar Sports” where people meet to catch up, watch games together, and read and comment on sports news. The idea of the BSD Cafe is the same – a bar where enthusiasts of BSD systems, Open Source, and technology can be found. And for me, although I might occasionally talk about users (out of technical habit), at the BSD Cafe, there are only “bar friends”.

The BSD Cafe is a place where we are “for”, not “against”. Supporters, not haters. Bar friends, not opponents. This doesn’t mean that opinions on other software can’t be expressed, even extremely negative ones (I do it myself from time to time), but the general spirit is that of open source: to build, to discuss, to understand. Wars against other solutions, especially if they are open source, are not part of the atmosphere of the BSD Cafe. We have our preferences – we support our ideas and solutions, but we are not here to “destroy” others. Among our users, there are people who develop Linux distributions – and for me, that is extremely positive!
When people are at ease and in a serene environment, they are often encouraged to be serene themselves. Some are negative and aggressive because they absorb it from their environment. Some users of the BSD Cafe have told me exactly this: the civil, friendly, relaxed, positive, and constructive level of the BSD Cafe is good for their mental health. Conversely, there are unfortunately people who find pleasure in causing trouble, in muddying the atmosphere. For these people, unfortunately, there is no solution, but the Cafe is not the place for them.
Political discussions can be part of our lives and daily routines, but the BSD Cafe is not a political group. In recent years, politics has become a topic not of discussion but of conflict. It has always been so to some extent, but commercial social media platforms have understood that hatred and conflict generate engagement, and engagement means selling advertising – a lot of advertising. Therefore, at the BSD Cafe, you might occasionally hear talk of politics or the political repercussions of technical decisions and choices. And that is perfectly okay. But it is not a place from which political conflicts should arise. We are for – supporters, not haters. We are here to build, not to destroy.
The BSD Cafe is therefore a place centered on the BSDs, and all services are, therefore, based on BSD operating systems.
All technologies used must be able to run “from my garage”. I am a professional – so this is not a hobby project – but it must not depend on any proprietary solution or “Cloud” solution. Today, there is a tendency to standardize (too much?) everything related to technical choices. If it’s pro, it’s Kubernetes/cloud/serverless/etc. – if it’s not, it’s “old” or “not pro”. I am, and have always been, a proponent of OwnYourData. And this is a mantra at the BSD Cafe. All services are based on Open Source solutions, outside the dynamics and centralized management of the usual companies. We must be free and maintain our technological autonomy; we cannot create a system where our communications and our data depend exclusively on third-party companies. I have enough experience to understand that, sooner or later, even the most solid companies can fail or change their business model. The BSD Cafe is therefore always in favor of self-hosting. Sometimes this means losing users, but not bar friends. It happens, in fact, that at a certain point, friends decide to try the BSDs and start self-hosting their own services. For me, that is a success: one less number in the statistics, but one more success on a technical and ideological level. And for all intents and purposes, they remain bar friends, even if their “handle” is different from “bsd.cafe” – it is the spirit, not an extension, that unites us.
From time to time, I have migrated the main VM of the BSD Cafe. Sometimes I have given notice, other times not (the downtime is minimal). In some cases, the system has run from my home desk, from the Mini PC I used as a home server and now use daily as a workstation. At the core of the technical choices, in fact, is the decision not to depend (strictly) on any specific technology or hardware. For this reason, the structure of the BSD Cafe is replicable and malleable, as well as described in its Wiki: it is a community of technology enthusiasts, and I want them to judge the choices transparently and autonomously, without hiding anything.
The BSD Cafe was not created to be just a Fediverse instance but, from the beginning, to provide a series of services powered by the BSDs for enthusiasts and friends of the BSDs. To date, the main services are:
Let’s get into the technical details:
The BSD Cafe is not “cloud ready”. The BSD Cafe was not created to be serverless. We love our servers, and we don’t need the “cloud” to run our services.

The BSD Cafe started with a FreeBSD VM on Hetzner in Finland for €3.29 per month. It is still active and is the primary for the entire infrastructure and is named “bsdcafevm”. It hosts the reverse proxy, in a jail, which routes all incoming connections, and is the “router” for the larger VM. This VM also hosts a “ns2” jail, which is the secondary DNS, and the “backup” instance of Mastodon, which helps with queue management and becomes primary when I shut down the other one during updates. For IPv6, Hetzner assigns a routed /64 block. I have divided it into /72 subnets so that I can route to other VPSs, services, etc., and provide an IPv6 address to any jail.
The main VPS, which hosts the services, called “bc01”, connects to this VM via Wireguard. bc01 has some particular characteristics, including:
A small VM (for one euro per month) based on FreeBSD that, within a jail, has the ns1 nameserver, which is the primary authoritative one. This VM also serves other purposes from time to time, such as monitoring the rest, etc.
A jail within one of my FreeBSD hosts in Poland, on OVH, contains the media files for the Mastodon instance. This is the most voluminous part of the entire hosting setup because Mastodon downloads and reprocesses all the multimedia content it encounters. This is for two main purposes: to clean it, in order to possibly remove malicious content, and to ensure that users of one’s own instance only have contact with their own media repository, not with that of the original instance – both for performance and privacy reasons. This server has spinning disks. Initially, I used Minio, but over time, performance plummeted. A few months ago, I migrated to SeaweedFS, and I am very satisfied with it. The outgoing bandwidth of this machine is not very wide, and I have other services on it. For this reason, I applied a solution that I described in an article on my blog.
I have used some VMs or physical hosts (spread across Europe and the USA) to act as a CDN. The BSD Cafe’s DNS will return the IP (both v4 and v6) closest to the caller, among those available, and this host will connect directly to the media server, then caching the content. The problem, in fact, does not arise when a user scrolls through their timeline, but as soon as they publish multimedia content: all known instances will connect to download and reprocess that file, generating a spike. This has little impact if it is a normal post, but it is extremely voluminous if it is content of a considerable size, like an image or a video. In this way, the various CDN nodes will download the content only once and serve it to all instances in their area of competence. These CDN nodes also do other things, can be activated or deactivated based on my needs, and are based on FreeBSD, NetBSD, and OpenBSD (one of them is on OpenBSD Amsterdam).
Another FreeBSD VPS (which I use for other things) contains “status.bsd.cafe“, which is the jail with Uptime Kuma that shows the status of the services or any of my communications about them. I do not receive notifications from this host, but from another monitoring system, so it is only to show the status of the situation.
In practice, the BSD Cafe mainly needs the “endpoint” VPS, the VPS with the services, and the jail with the media, which could be condensed into a single system if desired. Everything else is optional and I keep it active as I have resources available on external hardware.
Many of the technical choices have been documented in articles on my blog or in the BSD Cafe Wiki.
But all of this requires backups. And the BSD Cafe has a clear and defined backup procedure.
The main VPSs – namely bsdcafevm and bc01 – are based on FreeBSD and, therefore, ZFS. Both have the same type of backup, defined as follows:
Last but not least, the physical FreeBSD host on which bc01 currently rests is also backed up every 15 minutes to another external backup server, so the entire disk image. An additional layer of redundancy, to help me sleep better at night.
From a technical standpoint, therefore, I have tried to create a simple but secure infrastructure, with the most granular separation possible (for example: the main Mastodon instance has a jail for Mastodon, one for the Redis for the queues, etc., one for the Redis for the timeline caches (only in RAM, does not write to disk), and one for the database (PostgreSQL).
Then there are the common service jails (unbound for DNS resolutions, smtp for sending and receiving emails, etc.).
Being the Barista of the BSD Cafe is a privilege and an honor. The success of the project has exceeded my expectations, and this has filled me with joy. The BSD community is fantastic, mature, intelligent, and positive. The friends who approach the BSDs absorb all of this and transmit it to others, creating a virtuous circle. But it’s not always roses. There are problems, from time to time, that need to be solved. And, to quote my previous talk: “The main challenge is often ideological, not technical“.
Apart from the problems with blendit – Lemmy – which accumulates all the media it sees in a frenzied way and never deletes it, as well as having created serious update problems – all the software is on average stable and reliable.
The most complex part of my role as a barista, in fact, is not technical, but human: moderation. The techniques of scams and disturbances are constantly improving, and it is increasingly difficult to distinguish a new friend of the bar from a troublemaker. But the biggest challenge is maintaining balance.
Our philosophy is clear: to be for, not against. Supporters, not haters. This principle is a conscious choice, in stark contrast to the dominant model of commercial social media. These platforms are often designed around an engagement economy, where algorithms optimized to generate conflict and outrage maximize the time spent on the site and, consequently, advertising profits. The BSD Cafe rejects this model. We are not here to capitalize on anger, but to build a refuge from the toxicity of the internet.
This approach manifests itself in the way we handle controversial topics. Recently, a technical theme with strong political implications has begun to appear in discussions. My line is not to censor the topic itself. I firmly believe in open discussion. I only intervene when the discussion ceases to be a critical analysis and becomes a personal attack. For some, this is not enough: they would like a total ban on certain topics and the immediate exclusion of those who introduce them. My experience, however, has shown me that a more patient approach is often more constructive. I have seen people support controversial software solutions simply because they did not know their background. Thanks to civil and informative discussions, they have understood the context, thanked the community, and made more informed choices. Banning them instantly would have been unfair and would have denied everyone an opportunity for growth.
However, this philosophy of constructive positivity has attracted a specific criticism: that of promoting “Toxic Positivity”. The accusation is that, in our desire to maintain a serene environment, we end up excluding those who are suffering, invalidating their negative experiences because they “clash” with the atmosphere of the bar.
This is a criticism that I take very seriously, because it touches the heart of the project. And my answer is that it is a fundamental misunderstanding of our purpose. The goal is not to deny that pain, injustice, and suffering exist in the world. On the contrary: the BSD Cafe exists precisely because the world is often a difficult place.
Our purpose is not to pretend that those who suffer should stop suffering, but to offer them a place where, for a while, they may not be defined solely by their suffering. A place where they can be, first and foremost, a technology enthusiast, a FreeBSD expert, a curious OpenBSD user. A friend of the bar. We are always ready to support, console, and help those who need it, but we want to protect that mental space where shared passions unite us and give us relief.
Fortunately, this vision is confirmed by the very people we are trying to help. The number of private messages of appreciation I receive from people going through terrible times far exceeds the criticism. They write to me that “the civil, friendly, and constructive level of the BSD Cafe is good for their mental health”, because it allows them to disconnect from daily dramas that would otherwise be unbearable.
I am just the Barista. I can’t solve the world’s problems, but I can try to keep the counter clean, keep the machines running, serve a good (BSD) coffee, distribute (many) stickers, and ensure that, at least here, friends can find a moment of peace and constructive sharing. But a bar is nothing without its regulars. And the success of the BSD Cafe is not mine, but that of the BSD Community and the friends who are part of it. The richness of this place is not only the quality of the Coffee (which, being BSD, is very high), but mainly the human richness of the friends who are part of it. And to them, to all of you, I say thank you. From the bottom of my heart.
We need more bars and fewer shopping malls, and that is why I recently also founded the illumos Cafe. We want people who sit down, who socialize, or who simply enjoy the atmosphere of an environment that is familiar, friendly, and positive to them. Like this conference and all the BSD Conferences, because the environment is the same. Enough of shiny shop windows; a good hot drink, in the company of friends, can help you live better. “From the people, for the people“.
@linuxandyarn i think @stefano might be able to answer this. Or someone from #NetBSD community who has this setup.
We are counting down to the European *BSD event of the year! 😈⛳🐡
Big thank you to our gold sponsor: ARM
https://www.arm.com/
If you haven't secured your spot yet, now's the time!
https://tickets.eurobsdcon.org/
📅 You can check out the program at https://events.eurobsdcon.org/2026/schedule/
EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
September 09-13, 2026
#EuroBSDCon #EuroBSDCon2026 #BSD #RUNBSD #FreeBSD #NetBSD #OpenBSD
NetBSD. In FreeBSD’s bhyve. On a RK3566.
"Why?” you ask. Because I can.
"Why not OpenBSD?” you also ask. Because I can’t.
Was trying out virtualization on a Radxa Zero 3E. bhyve worked as expected for NetBSD, including networking. OpenBSD gets through the loader and looks like it's about to handoff to the kernel, then reboots. So close.
Ok, time to branch out in my #HomeServer configuration by switching the media server from #Debian to #NetBSD. (FreeBSD is embracing AI, so bleh.) Looks like the options are #MiniDLNA, which I played with once before, and #Gerbera and #MediaTomb, which I haven't.
Has anyone compared the three, especially on NetBSD, and to you have recommendations? I don't plan to run a desktop environment on the host.
@felimwhiteley @joeress @tubsta @latenightlinux
@fedops
Might I suggest a look at the BSDs? NetBSD has declared no AI, but is the most mysterious one. @stefano and @dwarmstrong are doing cool stuff with it.
Linux is living long enough to become the villain.
In a systemd suit.
edit: tags!
「 NetBSD is a stable, somewhat minimalist, and relatively slow-moving project. If you're willing to put some work in, this arguably makes it a refreshing change from the ever-accelerating techbro world of Linux 」
Why isn't Plex Server available for NetBSD, only FreeBSD?
I am aware it is also available for Windows, Linux, and macOS as well as different NAS platforms. I specifically would like to know why not NetBSD.
I was playing with something related to conference presentations idea here is prototype.
Let me know what do you think?
Day 1
With the release of NetBSD 11.0, and reading about the neat things people are doing with it (particularly on minimal hardware such as @stefano and the #littlefedi project), I want to explore this BSD in more detail. Hence "40 Days of NetBSD", where the plan is to poke around the system a bit each day for the next 40 days to gain a deeper appreciation for the OS and Unix tools.
NetBSD now installed on my Thinkpad T480s. Let's go!
Giving a new life to my X270 with NetBSD. Inspired by @stefano and @dwarmstrong
Coming from fvwm2 in OpenBSD, 15 minutes in and already like ctwm. Feel's familiar and it's fast!
#netbsd
dropQbsd porting from OpenBSD to FreeBSD almost complete: testing phase now. Same scripts run on both systems. mksh adopted for full BSD portability. Next challenge: include NextBSD.
The philosophy stays the same: few lines of code, no virtualization, dead-simple configuration. Compartmentalization without virtualization, built on BSD primitives. Most threat models, minimal attack surface.
https://git.sr.ht/~nobraininside/dropQbsd
#dropQbsd #openBSD #freebsd #netbsd #bsd #qubesOS #openSource #cybersecurity
We are counting down to the European *BSD event of the year! 😈⛳🐡
Big thank you to our silver sponsor: Netflix
https://www.netflix.com/
If you haven't secured your spot yet, now's the time!
https://tickets.eurobsdcon.org/
📅 You can check out the program at https://events.eurobsdcon.org/2026/schedule/
EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
September 09-13, 2026
#EuroBSDCon #EuroBSDCon2026 #BSD #RUNBSD #FreeBSD #NetBSD #OpenBSD
Oh duh, #ctwm supports opaque/live moving/resizing windows! How did I miss this all this time? XD
(in ~/.ctwmrc -- )
# hide window contents while altering windows for performance
#NoOpaqueMove
#NoOpaqueResize
#(comment those two out and reload)
I can't blame the #NetBSD folks for making the more performant option the default, even though I had opaque move/resize in (checks notes) 1995. ;)
(Of course, some folks might run the OS on older machines than that. It's technically possible!)
Now if I can just figure out how to move windows with the keyboard. Like, not a few pixels at a time, but snapping to the edges of the screen and other windows like you can in KDE Plasma. ;)
Since I already had the https://httpd.rocks domain (focusing on #OpenBSD) I figured it made sense to take advantage of the subdomain:
(Still placeholder until the guide is complete 😉 )
Built an open-source systems engineering learning log & roadmap to track my daily FreeBSD, NetBSD, OpenBSD, Linux, Go, and Rust studies.
• Built with Zola + Vanilla JS (0 dependencies)
• Sub-40ms static build
• Interactive diagrams & local progress tracking
• Works offline (PWA)
Live: https://deshmukhrahul.github.io/learning-log/
Code: https://github.com/deshmukhrahul/learning-log
#golang #rustlang #FreeBSD #NetBSD #OpenBSD #linux #opensource
Latest 𝗩𝗮𝗹𝘂𝗮𝗯𝗹𝗲 𝗡𝗲𝘄𝘀 - 𝟮𝟬𝟮𝟲/𝟬𝟴/𝟯𝟭 (Valuable News - 2026/08/31) available.
https://vermaden.wordpress.com/2026/08/31/valuable-news-2026-08-31/
Past releases: https://vermaden.wordpress.com/news/
#verblog #vernews #news #bsd #freebsd #openbsd #netbsd #linux #unix #zfs #opnsense #ghostbsd #solaris #vermadenday
Heya Fedi~ 
Anyone got a few words (Eng/Ger) they'd like to tell me about their experience with running #NetBSD as a server? Only answer if you are actually using it, have used it, or tried but failed to use it for this purpose!
I am also interested in #smolBSD, Podman (I've seen there's a port) and setting up and configuring both host and VM systems using Ansible, unless there is something more fit for it.
I'm not overly interested in FreeBSD or OpenBSD, but specifically in NetBSD.
We are counting down to the European *BSD event of the year! 😈⛳🐡
Big thank you to our silver sponsor: FreeBSD Foundation
https://www.freebsdfoundation.org/
If you haven't secured your spot yet, now's the time!
https://tickets.eurobsdcon.org/
📅 You can check out the program at https://events.eurobsdcon.org/2026/schedule/
EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
September 09-13, 2026
#EuroBSDCon #EuroBSDCon2026 #BSD #RUNBSD #FreeBSD #NetBSD #OpenBSD
Prompted by @aris, I added getopt-style long options to a #FreeBSD flavour of the #dd command, last night. Marc Teitelbaum added getopt to 4BSD ps(1) in 1990. Time for at least considering doing it for dd(1).
I changed the manual page, changed the Z shell completions, and even added some alternative spellings that use whole words.
This should be portable to #NetBSD and #OpenBSD with relative ease. GNU coreutils and BusyBox dd differ and need their own work, however.
Some napkin math for #BSD CVEs discovered with AI assistance:
#FreeBSD 27
#OpenBSD 1
#NetBSD 0
#DragonFlyBSD 0
The tragedy of #Debian accepting AI 'contributions' is that, most of the time, you are accepting stuff that:
a) is someone else's code, with all the potential legal issues (hence #NetBSD stance on it)
b) is of a very dubious quality, since it went through an AI blender
Just remember: an 'AI' does not exist and has no concept of code, quality and correctness -- I feel like we will soon see the first CVE with a CVSS 9.99 score in AI supplied slop vile coding due to this.
Funnily enough, I was never really into #Debian ... I appreciate the quality of the distro, but... I don't know, too many moving parts, I guess.
I will continue supporting #Slackware I'll look into #Guix and, of course, #OpenBSD and #NetBSD as well as #HardenedBSD .
The line is drawn. It is time to choose your side.
FIND yourself a a linux distribution or BSD that does reject AI; use it and donate to it.
If you can't move your daily driver move a secondary machine. Tinker with it, fit it into your life where it makes sense.
YEAH the linux kernel has slop. Most programming languages have slop. Most desktop environments have slop, you will have dependencies that are still slop. This is a big problem; there is no magic off switch to fixing this overnight.
We are in the early days of dealing with a contaminate that polluters are actively dumping into our digital environment.
It is going to take a long time before anyone can truly be slop free.
But support, and invest in the folks doing that hard work which will build a slop free future.
Starlight Network maintains a list of slop rejecting operating systems and distros here: https://noai.starlightnet.work/list.html #floss #AntiAI #linux #bsd #netbsd #elementaryos #gentoo
Sending good vibes to everyone in the Debian community navigating the recent transitions. If you're using this moment to do a little distro-hopping, consider jumping over to the BSD side. NetBSD offers a completely independent codebase built on a classic, predictable philosophy. You might just find your new permanent home! 🚩💻
#NetBSD #Debian #FOSS #noai #TechCommunity #antiai
nyu blog post,
Pengalaman install netbsd di tierhive
https://kusaeni.com/jurnal/menginstall-netbsd/
balas toots ini untuk berkomentar
We are counting down to the European *BSD event of the year! 😈⛳🐡
Big thank you to our bronze sponsor: Prodottoinrete
https://prodottoinrete.it/
If you haven't secured your spot yet, now's the time!
https://tickets.eurobsdcon.org/
📅 You can check out the program at https://events.eurobsdcon.org/2026/schedule/
EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
September 09-13, 2026
#EuroBSDCon #EuroBSDCon2026 #BSD #RUNBSD #FreeBSD #NetBSD #OpenBSD
I'm writing this post from a Raspberry Pi Zero W - 512 MB RAM, single-core ARMv6 - running NetBSD, powered by littleFedi. The process sits at 33 MB RSS, CPU basically asleep:
load averages: 0.05, 0.08, 0.09
CPU states: 0.0% user, 0.0% nice, 0.0% system, 1.0% interrupt, 99.0% idle
Memory: 301M Free
PID COMMAND RES STATE
2082 littlefedi-armv6 33M kqueue
No Redis. No PostgreSQL (but optional). No Sidekiq. No Node.js build pipeline. One statically-linked binary, one SQLite file, and the full fediverse experience. And this is the part people tend to miss: the same binary that runs happily on a Pi Zero scales, on the right hardware, to numbers that have nothing to do with "lightweight". It's not a toy that stays a toy. It's built to grow when you need it to.
Federation - Full ActivityPub S2S: WebFinger, NodeInfo 2.1, host-meta, HTTP Signatures with anti-impersonation checks. Per-user and shared inboxes, outbox, followers, following, featured collections. Thread completion with bounded on-demand fetching of missing ancestors/replies (separate sync and background budgets, all hard-capped). Quote posts via FEP-044f with the full approval handshake (QuoteRequest -> QuoteAuthorization), matching Mastodon 4.4 semantics, plus _misskey_quote and Fedibird quoteUri aliases. Account migration (Move), both outgoing and incoming, with alsoKnownAs linking, automatic follower migration, follow import from AP collections, and CSV export/import. Remote interaction discovery - async like/boost resolution from origin servers with REST fallback.
Mastodon API - Broad coverage: timelines (home, public, local, hashtag, bubble, direct), status CRUD with edits, scheduled posts, polls, bookmarks, lists (with replies_policy and exclusive), filters v2 (keyword CRUD), featured tags, followed hashtags (posts appear in home), markers, conversations, notifications with type exclusion, follow requests, blocks (federated Block/Undo), mutes with duration/expiry and hide_notifications, per-user domain blocks. OAuth2 with app registration, authorization code, client credentials and refresh_token flows, PKCE, consent screen, and scope enforcement (read/write/admin:read/admin:write). It talks fine to Elk, Tusky, Ivory, Phanpy, Semaphore and MastoBlaster.
Streaming - WebSocket and SSE. In-process pub/sub hub with per-connection send buffers, zero cost when no client is connected. Broadcast streams for public, local, remote, hashtags and lists. Per-account streams for user timeline, notifications and direct messages. Optional PostgreSQL LISTEN/NOTIFY backend for cross-process fan-out. Mastodon-compatible event serialization.
Push notifications - Full Web Push / VAPID (RFC 8030/8291) with aes128gcm encryption. Per-type alert toggles (mention, follow, reblog, favourite, poll, follow_request, status). Notify-bell support on followed accounts. Subscription expiry detection, rate-limit handling, 5-retry delivery.
Media pipeline - Upload processing: thumbnail generation (600x600), blurhash computation, EXIF stripping, magic-byte validation, SVG rejection, MIME mismatch detection, UUID-based file renaming. Size limits (40 MB default), pixel caps (16 MP default, tunable down to 4 MP for SBCs).
Media privacy proxy - This is the part I actually care about most. All remote media streams through the instance via HMAC-signed URLs (/proxy/media?url=...&sig=...), so local users never expose their IP address to remote servers. SSRF-guarded: DNS resolution check, private/CGNAT IP rejection, redirect re-validation. Pure io.Copy pass-through, no disk, no decode, ~32 KB buffer. Forwards HTTP Range requests for audio/video seeking. Configure a proxy_secret for stable URLs across restarts. On low-RAM devices, set cache_remote = "off" and you still see every image on the fediverse, the instance just doesn't store or process them.
Remote media caching - Three modes: off, eager (background sweep caches all remote attachments, avatars, headers and emoji, backfills existing on mode switch), lazy (cache on first access). Content-addressed, deduplicated by origin URL. Age-based pruning with file GC. Negative-cache for permanently dead URLs. Transparent origin fallback on cache miss. Open Graph preview cards stored durably with posts.
S3-compatible storage - A separate build tag (-tags s3), deliberately excluded from the default binary to keep it small. Supports AWS S3, MinIO, SeaweedFS, Ceph, Backblaze B2, Wasabi, DigitalOcean Spaces. Native media migration CLI: littlefedi admin media storage-migrate between local and S3 (DB-queue-backed, resumable, bounded batches). storage-status, storage-cancel, storage-resume commands. storage-manifest for rclone JSONL integration.
Markdown posts - Powered by goldmark with GFM extensions: tables, strikethrough, bare URL autolinking, hard wraps. Raw HTML deliberately not rendered. Output sanitized through bluemonday (defense-in-depth). Composer toggle in the web UI. Federates source.mediaType: text/markdown (Pleroma/GTS convention). Inbound Markdown source is rendered to HTML.
Visibility modes - The standard four (public, unlisted, private, direct) plus local-only (local, instance timeline only, never federates) and local unlisted (local_unlisted, followers only, no federation). Useful for notes to your own instance community.
Bubble timeline - Curated set of instances whose posts appear alongside local posts in a special timeline. Akkoma-compatible extension. Admin panel for adding/removing bubble instances. API endpoint at /api/v1/timelines/bubble.
Moderation - Account states: suspended (tombstone, federates Delete(Person)), silenced (visible to followers only, dropped from public timelines), quiet (like silenced plus it downgrades federation to followers-only, a middle ground I haven't seen anywhere else), disabled (cannot log in, content stays visible). Self-suspend prevention, last-admin-demotion guard. Blocks (bidirectional, federated), mutes (local-only, with duration and hide_notifications), per-user domain blocks (distinct from admin instance-wide blocks). Reports pipeline: user submissions plus inbound/forwarded Flag into an admin triage UI with resolution actions. Admin notification on new reports. Domain blocks with severity (noop/silence/suspend) plus Mastodon-parity options (reject_media enforced in the proxy, reject_reports, obfuscate, public). A moderation audit log records every admin action.
Web UI - Server-rendered HTML with html/template, templates embedded via //go:embed. Inline CSS (dark mode, Inter font, gradients). htmx 2.x and Alpine.js for progressive enhancement. No build step, no Webpack, no Tailwind, no npm. Every action works as a plain form POST without JavaScript. Works in Lynx, eLinks, text-only browsers, and on mobile.
Full feature set: home/public/local/bubble timelines with infinite scroll, profile pages with follow/unfollow/bell toggle, status threads with reply composer and background thread completion, post creation with CW, visibility selector (6 modes), media upload with alt text, Markdown toggle, quote posts (pre-loads composer with the quoted post as an inline card), post editing, composer autocomplete for @mentions and #hashtags, settings (display name, bio, password, sessions, moderation, pruning, account move, timeline preferences), report form, search page, tag management.
Admin panel - Dashboard (user counts, pending approvals, unreachable instances, open reports), accounts (with suspend/silence/quiet/disable/approve/reject actions), invites (CRUD), domain blocks (with severity and options), reports (triage and resolution), audit log, instance health (per-instance status with follower/following counts, reachability tracking, purge with typed-domain confirmation), bubble instances, settings, housekeeping (on-demand pruning), queue console (ready/scheduled/running/failed by job kind), media storage (S3 migration controls in S3 builds).
Background jobs - DB-backed queue that survives restarts, 8 job kinds: inbox, delivery (16 attempts over roughly 26h with capped exponential backoff and equal jitter), push_notification, actor_refresh, poll_close, scheduled_status, media_cache, media_migration. Per-instance circuit breaker suspends delivery at backoff_count >= 10. Actor refresh dispatcher with stale-while-revalidate, crash-safe leases, and per-actor exponential backoff.
Backups - Periodic or on-demand, server-side, no external tooling required. Each run produces a timestamped directory with config.toml, a portable database dump (VACUUM INTO for SQLite, pg_dump for PostgreSQL), an optional copy of owned media, and a manifest. Toggle it on, set an interval (24h, 7d, whatever fits), decide whether to include owned media (the remote cache is always excluded, no point backing up other people's content), and set a retention count so old backups get pruned automatically. Off by default, one line to turn on.
Housekeeping - Automated pruning: remote statuses by age, own low-interaction statuses (per-user or server thresholds, min likes/boosts caps), tombstones, expired mutes, stale media (>24h unattached), orphaned media (deleted posts), unreferenced media files (disk files with no DB record), cached media by age, cache file GC. On-demand controls in the admin UI.
Security - Token-bucket rate limiting per IP. Security headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Strict-Transport-Security. Content-Security-Policy with nonce-based script/style. CORS. CSRF on all cookie-authenticated POSTs. Session fixation protection. Password reset token in a cookie, not the URL. OAuth consent screen (not auto-issuing). SSRF protection (DNS, IP and redirect re-validation) on all outbound HTTP. HTTP Signature algorithm enforcement (rsa-sha256 only). Inbox body size limit (1 MB). Backfill goroutine cap. Thread-fetch amplification limits. File upload validation (magic bytes, SVG rejection, MIME mismatch). Username enumeration hardening.
Operational - Prometheus metrics at /metrics (counters for API/inbox/fed/web requests, statuses, deliveries, thread fetches, queue depth; gauges for workers, pending follows, uptime). Health checks (/health, /readyz). CLI: admin create-user, admin set-admin, admin list-users, admin suspend/unsuspend, admin invite generate/list/revoke, admin media prune/prune-orphans/prune-files, admin media storage-migrate/status/cancel/resume/manifest, post (publish from stdin/file with Markdown, visibility, CW, media, reply, quote), migrate (run migrations only). SMTP for password reset and notifications (falls back to stdout). Config via TOML file plus environment variables (LITTLEFEDI_{SECTION}_{KEY}).
Platform support - CGO-free, compiles with CGO_ENABLED=0. 23+ GOOS/GOARCH combos via the modernc SQLite driver: macOS (amd64, arm64), Linux (386, amd64, arm, arm64, loong64, ppc64le, riscv64, s390x), FreeBSD (386, amd64, arm, arm64), Windows (386, amd64, arm64), OpenBSD (amd64, arm64). NetBSD (amd64, arm, arm64) via a WASM-based fallback SQLite driver, I don't think anything else in the fediverse space explicitly targets NetBSD. PostgreSQL is a separate build tag (-tags postgres), S3 is another (-tags s3). The default binary carries neither, keeping it small. ARMv6 (GOARM=6) gets special treatment in the release naming, that's the Pi Zero target.
The fediverse shouldn't demand a beefy VPS. It shouldn't require Docker, 2 GB of RAM, Redis, Sidekiq, or a JS toolchain that pulls in 800 packages. A 10 euro Raspberry Pi Zero W running NetBSD, sitting on a shelf, drawing less than 2 watts, can be a fully functional fediverse instance with a web UI, mobile app compatibility, streaming, push notifications, quote posts, account migration, and a moderation toolkit. That's not hypothetical, that's what this post is running on.
But don't mistake "runs on a Pi Zero" for "only runs on a Pi Zero". Point the same binary at real hardware and it scales to numbers that have nothing to do with hobby-instance territory. Low power is the floor, not the ceiling.
One binary, one config file, one SQLite database. Light, yet complete.
I've been involved in this project for a while now, though I can't say much more about it at the moment, there are other people involved besides me and it's not entirely my call to talk about it publicly yet.
...let's lower the barriers even further!
Now this instance is running on a Raspberry Pi A+ (1 core @ 700 MHz, 256MB RAM), so even less than the Raspberry Pi Zero W it was running on before.
On NetBSD, of course!
#littleFedi #NetBSD #RunBSD #OwnYourData #Decentralization #OwnYourVoice
As of today, I believe NetBSD is one of the most important operating systems to consider for your deployments.
With hardware costs rising dramatically, portability and efficiency have become more important than ever. If prices do not come down, we will probably have to adapt and create new kinds of hardware, at lower cost. And NetBSD, by its very nature, will be very easy to port to that hardware.
Does it run on your modern PC? Maybe. Maybe not.
But it runs on your server. On your VPS. On your SBC. On your old computer, which may still have a lot to give, especially if you want to keep ownership of your own data.
And I know something about old hardware still having a lot to give:
https://it-notes.dragas.net/2023/08/27/that-old-netbsd-server-running-since-2010/
No jails or containerisation? smolBSD has already shown that a reduced NetBSD kernel can be so small that it can be started in milliseconds, while also adding the security benefits of virtualisation. A different concept, certainly. But one that already exists and can already be used.
Linux itself has opened up to AI. That is a choice I will not comment on.
But from now on, for those who do not want LLM-generated code in their operating system, there are essentially two options: fork Linux (!!!), or choose something different.
And NetBSD is that something different.
Already in 2024:
“...code generated by a large language model or similar technology (e.g. ChatGPT, GitHub Copilot) is presumed to be tainted (i.e. of unclear copyright, not fitting NetBSD's licensing goals) and cannot be committed to NetBSD.”
#NetBSD #RunBSD #smolBSD #IT #SysAdmin #OwnYourData #ModernTech
small mouse-shaped rock formation [he/him (they/them works too)] » 🌐
@algernon@come-from.mad-scientist.club
Come to think of it... what if I packaged #iocaine properly for #NetBSD, and submitted it to pkgsrc?
Or if not that, if I provided something pkgin can install (preferably a binary)?
I have a nix flake already, because NixOS is what I use. I have a Debian package, because that's been often requested, and was relatively simple to do. Both NixOS and Debian have a stance on LLMs I do not agree with - NetBSD has a much more reasonable policy. Thus, it feels like I should provide a package for that OS too.
I'll do that for 4.x, later.
Full disclosure: I personally have not used any BSDs before.
I am not sure whether the BSDs are really going to be those steadfast anti-AI warriors that some people make them out to be today in the light of the Debian-going-AI and Linux-going-AI news.
From what I can tell, the main philosophical difference between the various Linuxes and BSDs have always been two things:
BSDs generally seem to disagree with the copyleft ideal of the GNU licences and instead prefer their own lax, permissive licences that allow proprietary and all other kinds of nasty commercial uses. This does not appear to be a very trustworthy stance when we're talking about AI.
And regarding modularity, BSDs seem to err on the side of authority, preferring their base system to be one unified opinionated whole that's in turn designed to be as cohesive and functional as possible; while the Linuxes sacrifice that stability for user choice and modularity in a big patchwork. But this is also not a particularly appealing stance for someone who enjoys customisation and realises that sometimes, important software projects turn out to be problematic or compromised and need to be abandoned quickly.
#linux #debian #gnulinux #bsd #openbsd #netbsd #freebsd #ai #antiAi
Any idea how to create a keybind for super+. (period)?
This doesn't seem to work at all:
"." = mod4 : all : !"~/bin/emoji-picker"
Pressing super+. just gives me a period, and there's nothing in ~/.xsession-errors to indicate that it triggered anything at all.
Nevermind! Found the solution, derp:
"period" = mod4 : all : !"~/bin/emoji-picker"
@chadmccullough This saddens me as well, I recently started testing NetBSD for this reason, but I was holding out hope on this Debian vote, as it has been my preferred OS distribution for decades.
Oh, well. Time to put more energy into the testing of/transition to NetBSD. I also just updated my software donations rotation, replacing Debian with the NetBSD foundation.
We've all been there, but the #NetBSD way is different. Get the architecture right the first time. Why spend years fixing technical debt when you can build a stable, portable foundation from the start?
Reject automated bloat. RTAM( Read The Awesome Manual). Write code yourself. Run NetBSD.
#runBSD #UNIX #SoftwareEngineering #Craftsmanship #CodingMeme #OperatingSystems #antiai #noai
@jaypatelani #NetBSD is next on my list of things to explore. It seems like a beacon in the current tech mire of AI/corporate control.
If your i915 GPU glitches like in the post above under your #NetBSD 11, try creating an X config with X -configure, then change the device type from intel to modesetting in a freshly created xorg.conf.new, and then try running with this new config. This change has completely fixed visual snow and glitches on my Comet Lake GT2
Thanks to community driven projects like @netbsd we can take back the joy and ethics in computing. I'm in! ❤️🤗
Thank you for this wonderful operating system, and for keeping it away from Big tech LLM / GenAI.
#noAI #LLM #NetBSD
https://www.netbsd.org/developers/commit-guidelines.html
We are counting down to the European *BSD event of the year! 😈⛳🐡
Big thank you to our bronze sponsor: Genua
https://www.genua.de/
If you haven't secured your spot yet, now's the time!
https://tickets.eurobsdcon.org/
📅 You can check out the program at https://events.eurobsdcon.org/2026/schedule/
See you in Brussels!
EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
September 09-13, 2026
#EuroBSDCon #EuroBSDCon2026 #BSD #RUNBSD #FreeBSD #NetBSD #OpenBSD
RE: https://rpi0w.stefanomarinelli.it/@stefano/01a03e3d-1e73-7928-b396-db17b7f0f60b
@stefano is een bekende naam in BSD-kringen.
Hij plaatst regelmatig leuke dingen, zoals dit project. Hij heeft een Mastodon instance draaiend op een Raspberri onder NetBSD.
En kijk eens naar dat stroomverbruik!
Unix rocks.
#BSD #unix #NetBSD #Raspberri_pi
This is the first genuinely operational littleFedi instance.
It has been online since 1st July, is single-user (just me), and runs on a Raspberry Pi Zero W powered by NetBSD, directly on its SD card.
It consumes just under 1W.
Its database is this size:
-rw------- 1 little wheel 109289472 Aug 26 15:14 littlefedi.dbThat is, just a little over 100 MB. Yes, MB.
Its average CPU load is extremely low.
It is perfectly usable both from the web interface and from Mastodon API apps.
I have 179 followers and 169 followings, and it doesn't bat an eye.
I promise myself to use it more, and I will.
You don't need Big Tech to communicate with others.
You don't need an expensive data center to exist online.
Because we are people, and the bits are just extensions of our voice.