fediverse
#Sunrise #Delight 2 by Kaye Menner #Photography Wide variety #Prints & lovely #Products at:
https://kaye-menner.pixels.com/featured/sunrise-delight-2-by-kaye-menner-kaye-menner.html
#photograph #orangeblue #ocean #waves #earlysunrise #homedecor #mastoart #fediverse #fediart #fedigiftshop #giftideas #wallartforsale #Art #artforsale #BuyIntoArt #AYearForArt #Artist #FineArtAmerica #PhotographyFeed #VisualArts #CreativeArts
"Discourse on how these new open social networks should function are often framed in terms of ‘decentralization’, but I think that term has become a container that people can just project any property they like upon."
https://connectedplaces.online/reports/fr160-everyone-wants-servers-and-nobody-wants-servers/
via @fediversereport
#fediverse #atmosphere #decentralization #SocialMedia #communities
Week in Fediverse 2026-07-03
Servers
- TinyAP v0.1.10
- GoToSocial v0.22.0
- Mobilizon v5.2.4
- Bonfire v1.0.5
- PeerTube v8.2.2
- Ktistec v3.7.0
- PieFed v1.7.0
- Mastodon v4.6.3
- Hollo v0.9.6
- ActivityPub for WordPress v9.0.2
- NeoDB v0.16.3
- Wanderer v0.19.3
- Trunk & Tidbits, May 2026 (Mastodon)
- Lemmy Development Update June 2026 and 1.0.0-beta.1
Clients
- Fedilab v3.42.1
- Pachli v3.7.1
- Aria v1.5.5
- Rocinante v1.0.9
- Holos v1.12.0
- Mitra Mini v0.4.2
Tools and Plugins
- FediFetcher v7.1.21
- owncast-emojiwall v2.1.0
- Polls For ActivityPub (WordPress plugin)
For developers
- Why implementing ActivityPub is hard, and why it doesn't have to be (Fedify)
Protocol
- FEP-8c13: Context-Authority Routing with Object Integrity Proofs for Restricted Threads
- FEP-f228: Backfilling conversations (Final comments)
- FEP-7628: Move actor (Final comments)
-----
#WeekInFediverse #Fediverse #ActivityPub
Previous edition: https://mitra.social/objects/019f058a-b456-7c32-a9ee-f6ef93e8ee55
Good day all! Upcoming episode of Fireside Fedi!
Special Guest: @troler
Fully functional human written in Common Lisp. THERE IS NO WARRANTY FOR ME, TO THE EXTENT PERMITTED BY APPLICABLE LAW.
So don't miss it!
It will happen on 08/07/26 at 11:00 US Eastern Time ( UTC-4 )
🔥 FIRESIDE FEDI — FOLLOW ALL THREE! 🔥
📺 Live: @ozoned (#livestream)
🎬 VOD: @[email protected] (#Peertube #VOD)
🔔 Alerts: @when (new shows!)
Don't miss out — follow all three! #firesidefedi #fediverse #fedi #interview #freesoftware #opensource #userfreedom #freedom #resistance
The Speakeasy at Bardic Perspiration is a close-knit Mastodon server for misfits, rogues, and activists who all share a desire to make this and every world a better place.
This server has a post size of up to 1496 characters.
https://bardicperspiration.club
You can find out more at https://bardicperspiration.club/about or contact the admin account @Overgoddess
I generally agree with the sentiment that the fediverse is "big enough" and that it doesn't need to "grow", in terms of how many people are here.
That is, if we can grow the diversity of our community and at the same time kick out the gatekeepers.
Federated portfolio builder for photographers, illustrators and any sort of creatives. Something like #behance but federated and with custom themes. Would you use it?
#fediverse #needboost #boost #needhelp #fedidev #art #artists #artist #photography #illustration
Week in Fediverse 2026-04-24
Servers
- Hollo v0.7.11
- Lemmy v0.19.18
- Wafrn 2026.04.02
- Ibis v0.3.2
- Ktistec v3.3.6
- ActivityPub for WordPress v8.1.0
- Gush v0.0.36
- Iceshrimp.NET v2026.1-beta
- Mitra v5.2.0
- tootik v0.22.0
- NeoDB v0.14.0
- Vernissage Server v1.34.0
- PieFed v1.6.19
- ActivityPub Bots v1.1.1
Clients
- Jerboa v0.0.86
- Holos v1.4.0
Protocol
- FEP-35b7: Fediverse Servers, Instances, and Tenants
- FEP-ae49: Semantic Routing for ActivityPub
Articles
- Copyright and DMCA Best Practices for Fediverse Operators
-----
#WeekInFediverse #Fediverse #ActivityPub
Previous edition: https://mitra.social/objects/019d9ce7-bae8-7d4c-da66-27acb019a9e6
Ok, I'm testing something cool.
A blend of #snac, #Mastodon, #honk, #GoToSocial...and more.
This is running on a Raspberry PI Zero W, powered by NetBSD. The same that is powering my own smart thermostat. And it's quick.
I'll use this account and try to "stress" it.
Own your data. Always own your data!
Introducing #Betula v1.8.1, a self-hosted federated bookmark manager. Tags, notes, search, #Fediverse, archives, import and export.
No new features introduced. Instead, we polished the old ones.
We are also standardizing social bookmarking now. See https://w3id.org/fep/4772
We also contributed patches to Ties, Omnom, and Postmarks. They will soon federate compatible bookmarks.
https://joinbetula.org/v1.8.1.html
Sponsored by @nlnet
The future of social bookmarking is federated. May you be happy!
Fediverse ma lekkie problemy z tożsamością, nie umiem tego opisać, ale po prostu czegoś tu brakuje...
Memy i wszystko jest spoza fediverse, więc to nie pomaga... Niby jest spokojne, ale rozumiecie co mam na myśli, czegoś brakuje, by móc powiedzieć "Ah, kojarzy mi się fediverse" po jakiejś rzeczy
Brakuje czegoś kluczowego, ale nie umiesz lepiej zlokalizować czego :/
I just discovered the Fediverse (English) Wikipedia page has a huge section on AT Protocol and I question why. It seems like excessive promotion of Bluesky and its protocol that is not compatible with ActivityPub, both technically and in spirit. Illustrating bridging isn't the same as compatibility. Might as well add sections for other random network protocols like XMPP (Jabber).
I was debating whether I should share this here, but I do like getting feedback/yelled at, so here it goes:
A super simple, "normie"-friendly "please come back to Mastodon" page.
I just finished working on my first ATProto/Atmosphere/Bluesky app!
No, really. It helps you find your friends who have joined the fediverse.
Might be worth sharing with your friends!
#Dew-Kissed #Yellow #Gerbera #Daisies by Kaye Menner #Photography Wide variety #Prints & lovely #Products at:
#flowers #floral #droplets #yellowblack #homedecor #mastoart #fediverse #fediart #fedigiftshop #giftideas #wallartforsale #Art #artforsale #BuyIntoArt #AYearForArt #Artist #FineArtAmerica #PhotographyFeed #VisualArts #CreativeArts
A new release of TootSDK - 21.6.0 📣
https://github.com/TootSDK/TootSDK/releases/tag/21.6.0
What's changed:
- Support block quotes in attributed string renderer @luckkerr
Community contributions are greatly appreciated 🙌
It can be hard to understand how hashtags spread around the #fediverse, so I built a little tool to help you explore how visible hashtags are on different servers. The page also contains tips for how you can follow hashtags more effectively and help your own tagged posts get spread more broadly.
#Colorful #Teapot #Explosion by Kaye Menner
Need something colorful... Wide variety all #Prints styles & lovely #Products at:
#ai #digitalart #paint #bright #colorful #homedecor #mastoart #fediverse #fediart #fedigiftshop #giftideas #wallartforsale #Art #artforsale #BuyIntoArt #AYearForArt #Artist #FineArtAmerica #PhotographyFeed #VisualArts #CreativeArts
#Happy #Mothers #Day by Kaye Menner #2 Wide variety #Prints #GreetingCards & lovely #Products at:
https://kaye-menner.pixels.com/featured/2-happy-mothers-day-by-kaye-menner-kaye-menner.html
#cards #ai #art #digitalart #wishes #flowers #floral #text #homedecor #mastoart #fediverse #fediart #fedigiftshop #giftideas #wallartforsale #Art #artforsale #BuyIntoArt #AYearForArt #Artist #FineArtAmerica #PhotographyFeed #VisualArts #CreativeArts
🇨🇦🇺🇸📺️ It's the THU-THU July 2-9 weekly #Mastodon/ #Fediverse #WatchPartyCalendar ⬇️
⭐️️Special holiday schedules
#FridayThrillerClub🦈
#ColumboTV
#TheArk
#ReMonsterdon
📅LiveCal at http://bit.ly/MastodonWatchParties
⏰️️All times US Eastern
#Westerns #Music #Mysteries #scifi #Action #Comedy #anime #Movies #FilmMastodon #CineMastodon
TY hosts🌼 @MatthewTitus88 @MirrorAyako @Taweret @analgesicsleep @rsmon77 @hyde @greenpepper22 @kamikat @lilymarswrites @LisaMarieBowman @AlsoPaisleyCat @klu9 @heavydishongry
Toot.Garden is a Mastodon server for art, gaming, musings about the world, occasional memes and lighthearted jokes. Running since 2022, this server is dedicated to providing you a place to be social without being the product.
This server has a post size of up to 1000 characters.
You can find out more at https://toot.garden/about or contact the admin account @linkeddev
#FeaturedServer #Art #Gaming #Mastodon #Fediverse #FreeFediverse
RE: https://mastodon.social/@HolosSocial/116460942782444645
If some #iOS users are interested in joining a #Fediverse server that runs on your device, you can join the #HolosSocial project through #AltStore or drop an email at [email protected] to join TestFlight beta testers.
LittleFedi: light, yet complete
I'm writing this post from a Raspberry Pi Zero W - 512 MB RAM, single-core ARMv6 - running NetBSD, powered by littleFedi. The process sits at 33 MB RSS, CPU basically asleep:
load averages: 0.05, 0.08, 0.09
CPU states: 0.0% user, 0.0% nice, 0.0% system, 1.0% interrupt, 99.0% idle
Memory: 301M Free
PID COMMAND RES STATE
2082 littlefedi-armv6 33M kqueue
No Redis. No PostgreSQL (but optional). No Sidekiq. No Node.js build pipeline. One statically-linked binary, one SQLite file, and the full fediverse experience. And this is the part people tend to miss: the same binary that runs happily on a Pi Zero scales, on the right hardware, to numbers that have nothing to do with "lightweight". It's not a toy that stays a toy. It's built to grow when you need it to.
What LittleFedi actually ships
Federation - Full ActivityPub S2S: WebFinger, NodeInfo 2.1, host-meta, HTTP Signatures with anti-impersonation checks. Per-user and shared inboxes, outbox, followers, following, featured collections. Thread completion with bounded on-demand fetching of missing ancestors/replies (separate sync and background budgets, all hard-capped). Quote posts via FEP-044f with the full approval handshake (QuoteRequest -> QuoteAuthorization), matching Mastodon 4.4 semantics, plus _misskey_quote and Fedibird quoteUri aliases. Account migration (Move), both outgoing and incoming, with alsoKnownAs linking, automatic follower migration, follow import from AP collections, and CSV export/import. Remote interaction discovery - async like/boost resolution from origin servers with REST fallback.
Mastodon API - Broad coverage: timelines (home, public, local, hashtag, bubble, direct), status CRUD with edits, scheduled posts, polls, bookmarks, lists (with replies_policy and exclusive), filters v2 (keyword CRUD), featured tags, followed hashtags (posts appear in home), markers, conversations, notifications with type exclusion, follow requests, blocks (federated Block/Undo), mutes with duration/expiry and hide_notifications, per-user domain blocks. OAuth2 with app registration, authorization code, client credentials and refresh_token flows, PKCE, consent screen, and scope enforcement (read/write/admin:read/admin:write). It talks fine to Elk, Tusky, Ivory, Phanpy, Semaphore and MastoBlaster.
Streaming - WebSocket and SSE. In-process pub/sub hub with per-connection send buffers, zero cost when no client is connected. Broadcast streams for public, local, remote, hashtags and lists. Per-account streams for user timeline, notifications and direct messages. Optional PostgreSQL LISTEN/NOTIFY backend for cross-process fan-out. Mastodon-compatible event serialization.
Push notifications - Full Web Push / VAPID (RFC 8030/8291) with aes128gcm encryption. Per-type alert toggles (mention, follow, reblog, favourite, poll, follow_request, status). Notify-bell support on followed accounts. Subscription expiry detection, rate-limit handling, 5-retry delivery.
Media pipeline - Upload processing: thumbnail generation (600x600), blurhash computation, EXIF stripping, magic-byte validation, SVG rejection, MIME mismatch detection, UUID-based file renaming. Size limits (40 MB default), pixel caps (16 MP default, tunable down to 4 MP for SBCs).
Media privacy proxy - This is the part I actually care about most. All remote media streams through the instance via HMAC-signed URLs (/proxy/media?url=...&sig=...), so local users never expose their IP address to remote servers. SSRF-guarded: DNS resolution check, private/CGNAT IP rejection, redirect re-validation. Pure io.Copy pass-through, no disk, no decode, ~32 KB buffer. Forwards HTTP Range requests for audio/video seeking. Configure a proxy_secret for stable URLs across restarts. On low-RAM devices, set cache_remote = "off" and you still see every image on the fediverse, the instance just doesn't store or process them.
Remote media caching - Three modes: off, eager (background sweep caches all remote attachments, avatars, headers and emoji, backfills existing on mode switch), lazy (cache on first access). Content-addressed, deduplicated by origin URL. Age-based pruning with file GC. Negative-cache for permanently dead URLs. Transparent origin fallback on cache miss. Open Graph preview cards stored durably with posts.
S3-compatible storage - A separate build tag (-tags s3), deliberately excluded from the default binary to keep it small. Supports AWS S3, MinIO, SeaweedFS, Ceph, Backblaze B2, Wasabi, DigitalOcean Spaces. Native media migration CLI: littlefedi admin media storage-migrate between local and S3 (DB-queue-backed, resumable, bounded batches). storage-status, storage-cancel, storage-resume commands. storage-manifest for rclone JSONL integration.
Markdown posts - Powered by goldmark with GFM extensions: tables, strikethrough, bare URL autolinking, hard wraps. Raw HTML deliberately not rendered. Output sanitized through bluemonday (defense-in-depth). Composer toggle in the web UI. Federates source.mediaType: text/markdown (Pleroma/GTS convention). Inbound Markdown source is rendered to HTML.
Visibility modes - The standard four (public, unlisted, private, direct) plus local-only (local, instance timeline only, never federates) and local unlisted (local_unlisted, followers only, no federation). Useful for notes to your own instance community.
Bubble timeline - Curated set of instances whose posts appear alongside local posts in a special timeline. Akkoma-compatible extension. Admin panel for adding/removing bubble instances. API endpoint at /api/v1/timelines/bubble.
Moderation - Account states: suspended (tombstone, federates Delete(Person)), silenced (visible to followers only, dropped from public timelines), quiet (like silenced plus it downgrades federation to followers-only, a middle ground I haven't seen anywhere else), disabled (cannot log in, content stays visible). Self-suspend prevention, last-admin-demotion guard. Blocks (bidirectional, federated), mutes (local-only, with duration and hide_notifications), per-user domain blocks (distinct from admin instance-wide blocks). Reports pipeline: user submissions plus inbound/forwarded Flag into an admin triage UI with resolution actions. Admin notification on new reports. Domain blocks with severity (noop/silence/suspend) plus Mastodon-parity options (reject_media enforced in the proxy, reject_reports, obfuscate, public). A moderation audit log records every admin action.
Web UI - Server-rendered HTML with html/template, templates embedded via //go:embed. Inline CSS (dark mode, Inter font, gradients). htmx 2.x and Alpine.js for progressive enhancement. No build step, no Webpack, no Tailwind, no npm. Every action works as a plain form POST without JavaScript. Works in Lynx, eLinks, text-only browsers, and on mobile.
Full feature set: home/public/local/bubble timelines with infinite scroll, profile pages with follow/unfollow/bell toggle, status threads with reply composer and background thread completion, post creation with CW, visibility selector (6 modes), media upload with alt text, Markdown toggle, quote posts (pre-loads composer with the quoted post as an inline card), post editing, composer autocomplete for @mentions and #hashtags, settings (display name, bio, password, sessions, moderation, pruning, account move, timeline preferences), report form, search page, tag management.
Admin panel - Dashboard (user counts, pending approvals, unreachable instances, open reports), accounts (with suspend/silence/quiet/disable/approve/reject actions), invites (CRUD), domain blocks (with severity and options), reports (triage and resolution), audit log, instance health (per-instance status with follower/following counts, reachability tracking, purge with typed-domain confirmation), bubble instances, settings, housekeeping (on-demand pruning), queue console (ready/scheduled/running/failed by job kind), media storage (S3 migration controls in S3 builds).
Background jobs - DB-backed queue that survives restarts, 8 job kinds: inbox, delivery (16 attempts over roughly 26h with capped exponential backoff and equal jitter), push_notification, actor_refresh, poll_close, scheduled_status, media_cache, media_migration. Per-instance circuit breaker suspends delivery at backoff_count >= 10. Actor refresh dispatcher with stale-while-revalidate, crash-safe leases, and per-actor exponential backoff.
Backups - Periodic or on-demand, server-side, no external tooling required. Each run produces a timestamped directory with config.toml, a portable database dump (VACUUM INTO for SQLite, pg_dump for PostgreSQL), an optional copy of owned media, and a manifest. Toggle it on, set an interval (24h, 7d, whatever fits), decide whether to include owned media (the remote cache is always excluded, no point backing up other people's content), and set a retention count so old backups get pruned automatically. Off by default, one line to turn on.
Housekeeping - Automated pruning: remote statuses by age, own low-interaction statuses (per-user or server thresholds, min likes/boosts caps), tombstones, expired mutes, stale media (>24h unattached), orphaned media (deleted posts), unreferenced media files (disk files with no DB record), cached media by age, cache file GC. On-demand controls in the admin UI.
Security - Token-bucket rate limiting per IP. Security headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Strict-Transport-Security. Content-Security-Policy with nonce-based script/style. CORS. CSRF on all cookie-authenticated POSTs. Session fixation protection. Password reset token in a cookie, not the URL. OAuth consent screen (not auto-issuing). SSRF protection (DNS, IP and redirect re-validation) on all outbound HTTP. HTTP Signature algorithm enforcement (rsa-sha256 only). Inbox body size limit (1 MB). Backfill goroutine cap. Thread-fetch amplification limits. File upload validation (magic bytes, SVG rejection, MIME mismatch). Username enumeration hardening.
Operational - Prometheus metrics at /metrics (counters for API/inbox/fed/web requests, statuses, deliveries, thread fetches, queue depth; gauges for workers, pending follows, uptime). Health checks (/health, /readyz). CLI: admin create-user, admin set-admin, admin list-users, admin suspend/unsuspend, admin invite generate/list/revoke, admin media prune/prune-orphans/prune-files, admin media storage-migrate/status/cancel/resume/manifest, post (publish from stdin/file with Markdown, visibility, CW, media, reply, quote), migrate (run migrations only). SMTP for password reset and notifications (falls back to stdout). Config via TOML file plus environment variables (LITTLEFEDI_{SECTION}_{KEY}).
Platform support - CGO-free, compiles with CGO_ENABLED=0. 23+ GOOS/GOARCH combos via the modernc SQLite driver: macOS (amd64, arm64), Linux (386, amd64, arm, arm64, loong64, ppc64le, riscv64, s390x), FreeBSD (386, amd64, arm, arm64), Windows (386, amd64, arm64), OpenBSD (amd64, arm64). NetBSD (amd64, arm, arm64) via a WASM-based fallback SQLite driver, I don't think anything else in the fediverse space explicitly targets NetBSD. PostgreSQL is a separate build tag (-tags postgres), S3 is another (-tags s3). The default binary carries neither, keeping it small. ARMv6 (GOARM=6) gets special treatment in the release naming, that's the Pi Zero target.
Why it matters
The fediverse shouldn't demand a beefy VPS. It shouldn't require Docker, 2 GB of RAM, Redis, Sidekiq, or a JS toolchain that pulls in 800 packages. A 10 euro Raspberry Pi Zero W running NetBSD, sitting on a shelf, drawing less than 2 watts, can be a fully functional fediverse instance with a web UI, mobile app compatibility, streaming, push notifications, quote posts, account migration, and a moderation toolkit. That's not hypothetical, that's what this post is running on.
But don't mistake "runs on a Pi Zero" for "only runs on a Pi Zero". Point the same binary at real hardware and it scales to numbers that have nothing to do with hobby-instance territory. Low power is the floor, not the ceiling.
One binary, one config file, one SQLite database. Light, yet complete.
I've been involved in this project for a while now, though I can't say much more about it at the moment, there are other people involved besides me and it's not entirely my call to talk about it publicly yet.
Conoscete questo progetto?
Holos - Your Device is Your Fediverse Server
Holos turns your phone or computer into a full ActivityPub server. No big-tech hosting, no middleman reading your posts. A relay keeps your identity online 24/7 while your device stays in your pocket.
#fediverso #fediverse #activitypub #holossocial
https://holos.social/

