triptico.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Ángel Ortega in the fediverse, running snac
Admin email
angel@triptico.com
Admin account
@angel@triptico.com

Search results for tag #freebsd

[?]ltning » 🌐
@ltning@pleroma.anduin.net

Having an absolute blast at #EuroBSDCon as always. Loads of cool people, excellent tutorial on the #CRA and its implications for open source, very interesting #bhyve developments, a fantastic "debut" by Federico Angelilli bringing kernel live patching on #FreeBSD through his #GSOC project.

As always I brought some properly obsolete hardware: a 486slc2 running #NetBSD (or OS/2 on request), a Toshiba luggable 486SX2-66 with #DOS and #MonkeyIsland, #DOTT, #Larry, #SpaceQuest or whatnot, and - surprisingly - a Pentium 3-based Gericom laptop gifted to me by @outofcreativity which is now upgraded from #OpenBSD to NetBSD ;-)

#EuroBSDCon2026

Two screens from our booth: on the left showing Netscape 2.02 on OS/2 with the floppy museum page on #RecoveryWhiskers, on the right Monkey Island 1 running on the Toshiba.

Alt...Two screens from our booth: on the left showing Netscape 2.02 on OS/2 with the floppy museum page on #RecoveryWhiskers, on the right Monkey Island 1 running on the Toshiba.

Me on the train preparing the Toshiba. Big honkin' machine on the table, silly blue headphones on my head.

Alt...Me on the train preparing the Toshiba. Big honkin' machine on the table, silly blue headphones on my head.

    [?]Pete Orrall [Pete/Pete] » 🌐
    @peteorrall@mastodon.bsd.cafe

    I have some questions for the folks in the room:

    1.) What are the best practices for Poudriere and Packages. I understand one shouldn't mix Ports and packages, but I want to have some custom builds for my machines, like vim, zsh, wget, mutt, nano, while not relying on compiling everything. Is there a safe way to do this? Presumably one tracks the same quarterly ports tree as packages. But is there more to it?

    2.) When managing software using Poudriere and Ports, how does one manage emergency OOB patches? I would imagine switching Poudriere to use LATEST is an operational death wish.

      [?]vermaden » 🌐
      @vermaden@mastodon.bsd.cafe

      Latest 𝗩𝗮𝗹𝘂𝗮𝗯𝗹𝗲 𝗡𝗲𝘄𝘀 - 𝟮𝟬𝟮𝟲/𝟬𝟵/𝟭𝟰 (Valuable News - 2026/09/14) available.

      vermaden.wordpress.com/2026/09

      Past releases: vermaden.wordpress.com/news/

        [?]samurro » 🌐
        @samurro@fosstodon.org

        Is it supposed to be so obtrusive to install as a on a laptop with a DE? Configuring sysrc, manually editing lightdm although correct keyboard layout has been configured on installation? No username display just "User &", having to manually click and type your username and pw. Genuinely interested if FreeBSD is just not meant to be used as a desktop.

          [?]Bryan Steele :flan_beard: » 🌐
          @brynet@bsd.network

          [?]Erik L. Midtsveen » 🌐
          @midtsveen@mastodon.bsd.cafe

          How do you all desktop users, transfare files between an android phone and your desktops/laptops? ❤

            [?]Stefano Marinelli » 🌐
            @stefano@mastodon.bsd.cafe

            PFWall: building firewall images to run at scale - the last presentation of this wonderful conference

            Ready to present the firewall slides

            Alt...Ready to present the firewall slides

              Tomáš boosted

              [?]jdkiser » 🌐
              @jdkiser@social.sdf.org

              DaemonForums is offline as its owner/administrator j65nko is terminally ill and in the hospital. DaemonForums was a *BSD forum and community for nearly 20 years, a replacement when BSDForums was taken over by spambots around 2008. There was a lot of good information and discussion there over the years. forums.freebsd.org/threads/dae

                [?]Stefano Marinelli » 🌐
                @stefano@mastodon.bsd.cafe

                Olivier: supporting hibernate (s4) on FreeBSD

                Olivier is presenting

                Alt...Olivier is presenting

                  [?]EuroBSDCon » 🌐
                  @EuroBSDCon@bsd.network

                  Laatste dag van de European *BSD event of the year! 😈⛳🐡

                  The last day of the event starts today!

                  Registration and ☕☕☕ starts at 09:00

                  The second keynote starts at 09:30 in D.0.02, The current state of "Green AI" by Anne Currie.

                  After the break at 10:30, there will be three tracks, also streaming via Peertube and Youtube:

                  - D.0.02
                  exquisite.tube/w/dFceGLUNjX8ni

                  - D.0.03
                  exquisite.tube/w/2WFqRYvcpmYAE

                  - D.0.07
                  exquisite.tube/w/bPdoz2UUAxACH

                  There is a 15 minute break between each talk to give you plenty of time to move from one room to another and grab some ☕
                  Lunch will be served after the family picture at 12:30. :)

                  At 18:15 the closing session of EuroBSDCon will be in D.0.02

                  You can find the full program and streams at: 2026.eurobsdcon.org/program.ht

                  EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
                  September 09-13, 2026

                    [?]Peter N. M. Hansteen » 🌐
                    @pitrh@mastodon.social

                    [?]Stefano Marinelli » 🌐
                    @stefano@mastodon.bsd.cafe

                    Baptiste presenting: rcd(8): modern service manager the FreeBSD way

                    Baptiste is presenting

                    Alt...Baptiste is presenting

                      [?]Stefano Marinelli » 🌐
                      @stefano@mastodon.bsd.cafe

                      Lukas is presenting: pkgbase in Production: A Practical Overview

                      Lukas is ready to start

                      Alt...Lukas is ready to start

                        [?]𝙹𝚘𝚎𝚕 𝙲𝚊𝚛𝚗𝚊𝚝 ♑️🤪 » 🌐
                        @joel@gts.tumfatig.net

                        Haha, been there, asked that 😆

                        #FreeBSD #EuroBSDcon #EuroBSDcon2026

                          [?]YRabbit » 🌐
                          @yrabbit@mastodon.sdf.org

                          @RueNahcMohr Yeah, that happens - upgrading one virtual Linux instance (my main systems are ) ended in a quiet death after booting the latest kernel. I had to select the old kernel in GRUB and set it as the default.

                          Then there’s another one that decides to recompile certain kernel modules during an update and fails at it. Now, whenever I install any package, it keeps trying to recompile that damn module over and over - but at least it still runs.

                            [?]Ricardo Martín :bsdhead: » 🌐
                            @ricardo@mastodon.bsd.cafe

                            [?]maxfx » 🌐
                            @martin@mastodon.bsd.cafe

                            Hi,
                            SoCBSD is a new FreeBSD fork focused on bringing FreeBSD support to embedded systems and SoCs.

                            The project is just getting started, and we’re working on drivers, board support, and improving FreeBSD on ARM-based platforms.

                            👉 github.com/SoCBSD

                            Contributions, testing, feedback, and ideas are very welcome!

                            ,

                              [?]0x0 » 🌐
                              @0x0@hachyderm.io

                              @ax6761
                              When I tried installing I ran into the same issues: the boot screen would freeze. Eventually I solved that with but maybe I'll try Net again.
                              Had no issues installing and running both and

                                [?]JdeBP » 🌐
                                @JdeBP@mastodonapp.uk

                                @rl_dane

                                Maybe you learned in the interim. (-:

                                By the way, you made me re-visit the doco for case. It should be ;& (just the one semi-colon) to fall through in all sh-conforming shells, because that was standardized back in 2024. and knew it was coming in 2017 and adjusted their Almquist shells.

                                And I realized that I've been writing for a highest common factor that is actually too low, because the manual for sh(1) is wrong. They kept the shell conformant, but didn't keep the doco in synch.

                                  [?]R.L. Dane :Debian: :FreeBSD: :OpenBSD: :NetBSD:🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
                                  @rl_dane@polymaths.social

                                  @JdeBP

                                  Maybe you learned #VHDL in the interim.  (-:

                                  Uh, NO, do you see me staring far off into the distance and drooling? 😂

                                  By the way, you made me re-visit the doco for case.  It should be ;& (just the one semi-colon) to fall through in all sh-conforming shells, because that was standardized back in 2024.  #NetBSD and #FreeBSD knew it was coming in 2017 and adjusted their Almquist shells.

                                  And I realized that I've been writing for a highest common factor that is actually too low, because the #FreeBSD manual for sh(1) is wrong.  They kept the shell conformant, but didn't keep the doco in synch.

                                  Huh, I tried sh, ksh, mksh, and bash with ;;, ;&, ;;&, and ;| on NetBSD, and the only ones that worked were bash and ksh.

                                  (Ok, I see how I miscommunicated here. I meant the only ones where ;;& or ;| worked, not ;&)

                                  On this Devuan box, bash accepts ;;, ;&, and ;;& just as the manpage states (short-cut, accept all after first accpetance, evalute all, respectively)
                                  mksh works just like bash, but also accepts ;| as equivalent to bash's ;;& (which it also accepts)
                                  Dash's sh (debian almquist) only accepts ;;, and gives an execution-stopping syntax error with all of the other forms.

                                  On a freebsd server I tried, ksh (ksh93) only accepts ;; and ;&. sh acts the same. Tried an OpenBSD server and got the same result.

                                  Here's the test script:

                                  echo
                                  echo 'trying ;;'
                                  case a in a) echo its a;; b) echo its b;; *) echo its something;; esac
                                  echo
                                  echo 'trying ;&'
                                  case a in a) echo its a;& b) echo its b;& *) echo its something;& esac
                                  echo
                                  echo 'trying ;;&'
                                  case a in a) echo its a;;& b) echo its b;;& *) echo its something;;& esac
                                  echo
                                  echo 'trying ;|'
                                  case a in a) echo its a;| b) echo its b;| *) echo its something;| esac
                                  

                                    [?]JdeBP » 🌐
                                    @JdeBP@mastodonapp.uk

                                    @rl_dane

                                    The has supported ;& for years. I was just reading the CVS changelog to see when it was added to its manual, which was back in 2017.

                                    It definitely works.

                                    The Almquist Shell has supported ;& for years. I actually have a 2017 version of that.

                                    It definitely works, too.

                                    Neither the Xu Debian Almquist Shell nor the Debian Almquist Shell (Herbert Xu is maintaining the two in parallel for some reason, and they are different.) support ;& .

                                    A terminal session in mostly white on black.  At the coloured Z shell prompt, uname shows that the system is NetBSD, and the NetBSD Almquist shell and the Debian Almquist shell are run with a small case statement that uses ";&".  The NetBSD Almquist shell can be seen working, and the Debian Almquist shell failing.

                                    Alt...A terminal session in mostly white on black. At the coloured Z shell prompt, uname shows that the system is NetBSD, and the NetBSD Almquist shell and the Debian Almquist shell are run with a small case statement that uses ";&". The NetBSD Almquist shell can be seen working, and the Debian Almquist shell failing.

                                    A terminal session in mostly white on black.  At the coloured Z shell prompt, uname shows that the system is FreeBSD, and the FreeBSD Almquist shell and the Debian Almquist shell are run with a small case statement that uses ";&".  The FreeBSD Almquist shell can be seen working, and the Debian Almquist shell failing.

                                    Alt...A terminal session in mostly white on black. At the coloured Z shell prompt, uname shows that the system is FreeBSD, and the FreeBSD Almquist shell and the Debian Almquist shell are run with a small case statement that uses ";&". The FreeBSD Almquist shell can be seen working, and the Debian Almquist shell failing.

                                      [?]JdeBP » 🌐
                                      @JdeBP@mastodonapp.uk

                                      @rl_dane

                                      I do not use it in shell script, and the lack of it in the Almquist Shells obviously inhibits its spread on several operating systems; but in compiled languages rather than interpreted ones: yes, people use it all of the time. And our compilers nowadays nag us when we don't put in the [[clang:yes, I bloody know it's falling through]]; markers in our code.

                                      The Bournist shell syntax pretty obviously has its roots in trying to provide something that the C shell had been providing since the late 1970s.

                                      An amusing thing here is that when I was working on that dash patch I accidentally implemented the ;| behaviour by mistake, initially. It's actually simpler to implement. But I was aiming merely to bring Xu's dash to parity with the and Almquist shells, rather than add a feature that they don't have, so I didn't keep the mistake. (-:

                                      @mirabilos

                                        [?]Mason Loring Bliss [he, him, his] » 🌐
                                        @mason@partychickens.net

                                        I wrote this to a FreeBSD luminary who posts a lot about the harms of LLMs. Heard nothing back so I'll open it up to the community. I don't get how LLMs can be dangerous, but FreeBSD using them is okay...? Anyway, comments welcome:

                                        ...

                                        Hey, a question for you. I'm fond of FreeBSD. This Mastodon instance runs on it, for example. But the noises I'm hearing suggest a pro-slop FreeBSD policy on the way.

                                        You post enough stuff that indicates you see the dangers that you must have some thoughts about FreeBSD approaching slop, and I'd love to hear them. I truly hate the notion of having to give up so much technology I love because of this stuff, but the slop has to be opposed for a variety of reasons.

                                          [?]FreeBSD Foundation » 🌐
                                          @FreeBSDFoundation@mastodon.social

                                          FreeBSD 14.5-RELEASE is now available!

                                          As the sixth release of the stable/14 branch, FreeBSD 14.5 focuses primarily on maintenance, including bug fixes, driver updates, and updated versions of externally maintained software.

                                          For new systems, users are encouraged to deploy FreeBSD 15.1.

                                          Explore the release notes and learn more: freebsd.org/releases/14.5R/ann

                                            [?]0x0 » 🌐
                                            @0x0@hachyderm.io

                                            Well... it looks as though i can get on a M73 (SFF). As soon as the boot screen shows up it freezes.
                                            Any other with support out there? Or maybe linux?

                                              [?]Evilham :antifa: » 🌐
                                              @evilham@fedi.unchat.cat

                                              @ricardo latest 15.1, direct off freebsd.org's big download button.

                                              Real hardware though, could be the difference. IIRC there have been other reports, dismissed as "not a problem" with a VM screenshot as well.

                                              As mentioned, this is not a proper bug report. It's more: "I am an experienced #FreeBSD user that contributes patches whenever possible, and still this kind of thing happens. There is something here worth looking into, because we are doing something wrong."

                                              Once I manage to setup my machine again I will certsinly take a good look at bsdinstall zfsboot, there are a couple things that seem off.

                                                [?]Stefano Marinelli » 🌐
                                                @stefano@mastodon.bsd.cafe

                                                EuroBSDCon is not a traditional conference, but a family gathering. The kind of family you like, the one you choose, the one that always makes you feel at home.

                                                As soon as we landed, we dropped our bags off at the hotel luggage room and rushed straight to the conference venue.

                                                It was fantastic to meet old and new friends again, with that kind of welcome that only BSD conferences can give you.

                                                I've only had the chance to talk to a fraction of the people I'll meet over the next few days, and to me, that's fantastic.

                                                Close-up of a EuroBSDCon 2026 speaker badge on a red lanyard, lying on a white fabric surface. The badge reads "Stefano Marinelli, BSD Cafe Barista" and features the EuroBSDCon logo, "Speaker" label, QR codes, BSD-themed artwork, and "Brussels, 9th - 13th Sep. 2026".

                                                Alt...Close-up of a EuroBSDCon 2026 speaker badge on a red lanyard, lying on a white fabric surface. The badge reads "Stefano Marinelli, BSD Cafe Barista" and features the EuroBSDCon logo, "Speaker" label, QR codes, BSD-themed artwork, and "Brussels, 9th - 13th Sep. 2026".

                                                  [?]Mark McBride » 🌐
                                                  @markmcb@mas.to

                                                  NetBSD. In FreeBSD’s bhyve. On a RK3566.

                                                  "Why?” you ask. Because I can.
                                                  "Why not OpenBSD?” you also ask. Because I can’t.

                                                  Was trying out virtualization on a Radxa Zero 3E. bhyve worked as expected for NetBSD, including networking. OpenBSD gets through the loader and looks like it's about to handoff to the kernel, then reboots. So close.

                                                    [?]Evilham :antifa: » 🌐
                                                    @evilham@fedi.unchat.cat

                                                    Since #FreeBSD people are already at #EuroBSDcon, here is a complain in the void (*):
                                                    It looks like the installer ignores the desire to encrypt the disk when using ZFS.
                                                    Realised this after setting up things and rebooting, and noticing "hey, it's not asking for the passphrase".
                                                    And, boy do I have some thoughts regarding bsdinstall zfsboot.

                                                    (*) haven't gotten the spoons yet for a proper bug report, but it will come once things are back to normal

                                                      [?]Erik L. Midtsveen » 🌐
                                                      @midtsveen@mastodon.bsd.cafe

                                                      22:52—Good night ! ❤

                                                        [?]EuroBSDCon » 🌐
                                                        @EuroBSDCon@bsd.network

                                                        Counting down, for real now, to the European *BSD event of the year! 😈⛳🐡

                                                        stagetimer.io/r/X21SK1YB/

                                                        📅 You can check out the program at https://
                                                        events.eurobsdcon.org/2026/schedule/

                                                        EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
                                                        September 09-13, 2026

                                                        Image of Homer Simpson on a blue background with the text:

Let the countdown begin

                                                        Alt...Image of Homer Simpson on a blue background with the text: Let the countdown begin

                                                          [?]BastilleBSD :freebsd: » 🌐
                                                          @BastilleBSD@fosstodon.org

                                                          When your jails are on a private network how do you reach them from the outside? Redirect the port from the host:

                                                          bastille rdr TARGET tcp 443 443
                                                          bastille rdr TARGET tcp 2200 22

                                                          List them with bastille rdr TARGET list, clear with ... clear.

                                                          VNET jails don't need and don't use this.

                                                            [?]David Chisnall (*Now with 50% more sarcasm!*) » 🌐
                                                            @david_chisnall@infosec.exchange

                                                            I don’t think I’ve upgraded any of my systems to 15. This is probably the longest I’ve gone after a new release without upgrading at least some machines (14.5 just came out). I even ran FreeBSD 5.0.

                                                            I don’t have any reason for avoiding 15, it’s just that I don’t really have a reason to upgrade. 14 was more than good enough. A more stable pkgbase would be a compelling reason, as would rcd landing. So I’m actually quite excited for 16.

                                                              [?]gmc » 🌐
                                                              @gmc@snac.chasmcity.net

                                                              The update of the port of to 2.95 has been merged! And it's even been merged into the current quarterly branch. I guess that's because of the patched DOS vulnerability.

                                                              Screenshot of the snac entry on the FreeBSD website, showing it is at verson 2.95.

                                                              Alt...Screenshot of the snac entry on the FreeBSD website, showing it is at verson 2.95.

                                                                [?]EuroBSDCon » 🌐
                                                                @EuroBSDCon@bsd.network

                                                                Safe travels for everybody who is making their way to the European *BSD event of the year! 😈⛳🐡

                                                                📅 You can check out the program at https://
                                                                events.eurobsdcon.org/2026/schedule/

                                                                EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
                                                                September 09-13, 2026

                                                                4 images of Tom Hanks in in different roles. The first 3 images (probably) from Cast Away the last from (probably) The Terminal.

The first image is an exited Tom Hanks and has the text: "First Day Traveling" 
Second image, looking more serious with the text: "Counting days left".
Third image looking desperate and a little beat, "Last day".
The last image looking anxiously in the camera, "Waiting at airport".

                                                                Alt...4 images of Tom Hanks in in different roles. The first 3 images (probably) from Cast Away the last from (probably) The Terminal. The first image is an exited Tom Hanks and has the text: "First Day Traveling" Second image, looking more serious with the text: "Counting days left". Third image looking desperate and a little beat, "Last day". The last image looking anxiously in the camera, "Waiting at airport".

                                                                  [?]vermaden » 🌐
                                                                  @vermaden@mastodon.bsd.cafe

                                                                  Latest 𝗩𝗮𝗹𝘂𝗮𝗯𝗹𝗲 𝗡𝗲𝘄𝘀 - 𝟮𝟬𝟮𝟲/𝟬𝟵/𝟬𝟳 (Valuable News - 2026/09/07) available.

                                                                  vermaden.wordpress.com/2026/09

                                                                  Past releases: vermaden.wordpress.com/news/

                                                                    [?]Erik L. Midtsveen » 🌐
                                                                    @midtsveen@mastodon.bsd.cafe

                                                                    Hey folks! 🐡

                                                                    I recently, as of yesterday, installed FreeBSD on my ThinkPad E14 Gen 4, and will document my journey coming from Debian GNU/Linux over to something that is BSD.

                                                                    I’ve had some knowledge of FreeBSD from past interactions here on Mastodon, as well as from YouTube and other social media platforms. My ThinkPad also has two ssd drives, so I decided to wipe one of them and install FreeBSD, and using it as my daily driver.

                                                                    I used to be on kolektiva.social a while back. Not sure how long I’ll stick around on this one either, but I came across bsd.cafe while reading through some FreeBSD documentation and figured I’d join.

                                                                    Feel free to boost me if you remember me, or not, no worries!

                                                                    Also, here are some relevant and useful links to check out:

                                                                    freebsd.org/
                                                                    docs.freebsd.org/en/books/hand

                                                                    Screenshot of the LXQt desktop environment with a fullscreen terminal window displaying the output of fastfetch, a command-line utility that shows system information such as the operating system, hardware, kernel, and desktop environment.

                                                                    Alt...Screenshot of the LXQt desktop environment with a fullscreen terminal window displaying the output of fastfetch, a command-line utility that shows system information such as the operating system, hardware, kernel, and desktop environment.

                                                                      [?]Erik L. Midtsveen » 🌐
                                                                      @midtsveen@mastodon.bsd.cafe

                                                                      makes me wanna understand computers again! ❤

                                                                        [?]Erik L. Midtsveen » 🌐
                                                                        @midtsveen@mastodon.bsd.cafe

                                                                        As a new user, I’ve genuinely come to love working in a TTY. There’s something incredibly satisfying about navigating, configuring, and using my OS straight from the terminal! 😍

                                                                          [?]Erik L. Midtsveen » 🌐
                                                                          @midtsveen@mastodon.bsd.cafe

                                                                          Hi , how’s development going on the MediaTek MT7921 Wi-Fi 6 (802.11ax) driver? Is there currently any progress toward getting it supported?

                                                                            [?]BastilleBSD :freebsd: » 🌐
                                                                            @BastilleBSD@fosstodon.org

                                                                            Manpage Monday: bastille pkg

                                                                            Manage packages inside your jails without ever consoling in.

                                                                            Install nginx in myjail
                                                                            > bastille pkg myjail install nginx

                                                                            Use the host's pkg binary instead of the jail's
                                                                            > bastille pkg -H myjail install nginx

                                                                            Works with any pkg args: update, upgrade, search, audit, info, etc

                                                                              [?]Peter N. M. Hansteen » 🌐
                                                                              @pitrh@mastodon.social

                                                                              There will be a PF tutorial at EuroBSDCon 2026 in Brussels:

                                                                              Network Management with the PF Packet Filter Toolset on OpenBSD and FreeBSD
                                                                              Featuring Tom Smyth and Peter Hansteen, 2026-09-11, 10:30, full day

                                                                              See events.eurobsdcon.org/2026/tal
                                                                              To register: tickets.eurobsdcon.org/eurobsd

                                                                                [?]Peter N. M. Hansteen » 🌐
                                                                                @pitrh@mastodon.social

                                                                                Learn about software engineering for cyber resiliency at EuroBSDcon 2026 in Brussels:

                                                                                The night before CRAmas - why EU regulations are a gift to open source
                                                                                Alice Sowerby, Pierre Pronchery and Peter Hansteen 2026-09-10, 10:30 full day

                                                                                See events.eurobsdcon.org/2026/tal
                                                                                To register: tickets.eurobsdcon.org/eurobsd

                                                                                  [?]EuroBSDCon » 🌐
                                                                                  @EuroBSDCon@bsd.network

                                                                                  We are counting down to the European *BSD event of the year! 😈⛳🐡

                                                                                  For when you need another reason to come to EuroBSDCon 2026, the closing auction!

                                                                                  Don't forget to bring your monies!!

                                                                                  If you haven't secured your spot yet, now's the time!
                                                                                  https://
                                                                                  tickets.eurobsdcon.org/

                                                                                  📅 You can check out the program at https://
                                                                                  events.eurobsdcon.org/2026/schedule/

                                                                                  EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
                                                                                  September 09-13, 2026

                                                                                  Image of two plush Puffies in an empty suit case.

                                                                                  Alt...Image of two plush Puffies in an empty suit case.

                                                                                    [?]Mason Loring Bliss [he, him, his] » 🌐
                                                                                    @mason@partychickens.net

                                                                                    I'm dismayed that the three systems and communities I love the most, Debian, FreeBSD, and Slackware, are falling into the trap we might call "Uncanny Valley as a Service".

                                                                                    Debian has their pro-slop policy now, and FreeBSD and Slackware both have influential developers who are pro-slop. FreeBSD is shooting for a "balanced" policy - but how do you balance the copyright and license violations, the cognitive harm, and the climate impact against a dubious "convenience?" And I don't expect Slackware will say anything formal.

                                                                                    I'm hoping I can rekindle my fondness for NetBSD, and I've probably got Gentoo in my future for desktops. I know I can live with NetBSD and if I set up a local binary build server I can minimize the energy cost of having to compile everything for Gentoo. (Maybe if I figure out the implications of the USE flags from default/linux/amd64/23.0/desktop/gnome that'll end up being reasonable. I'm not a G.N.O.M.E. user. See wiki.gentoo.org/wiki/Gentoo_bi )

                                                                                      [?]vermaden » 🌐
                                                                                      @vermaden@mastodon.bsd.cafe

                                                                                      New 𝗔𝗠𝗗 𝗕𝗮𝘀𝗲𝗱 𝗙𝗿𝗲𝗲𝗕𝗦𝗗 𝗗𝗲𝘀𝗸𝘁𝗼𝗽 𝗥𝗲𝗹𝗼𝗮𝗱𝗲𝗱 [AMD Based FreeBSD Desktop Reloaded] article on vermaden.wordpress.com blog.

                                                                                      vermaden.wordpress.com/2026/09

                                                                                        Tomáš boosted

                                                                                        [?]Justine Smithies [She / Her] » 🌐
                                                                                        @justine@snac.smithies.me.uk

                                                                                        For all those lovers running a which of the following shells would you recommend and why ? Let it be noted that I'm currently running on just now but have wondered about ksh-devel ksh93u+m the development branch ksh93 based on AT&T ksh93u+ (stable).
                                                                                        Am I missing out on anything here ?

                                                                                        https://github.com/ksh93/ksh


                                                                                          [?]𝙹𝚘𝚎𝚕 𝙲𝚊𝚛𝚗𝚊𝚝 ♑️🤪 » 🌐
                                                                                          @joel@gts.tumfatig.net

                                                                                          Yesterday, I tried deploying #invidious on #FreeBSD using #podman (and podman-compose). The only thing that failed was the postgresql container… 😳 The was an error about missing fd something probably due to the Linux emulation stack… Even the classical pgsql container does not start… 🤔

                                                                                          Anyone is successfully running pgsql using a Linux container?

                                                                                          PS: no, I don’t want to run a native pgsql. because $REASONS

                                                                                            It's Just Me boosted

                                                                                            [?]Stefano Marinelli » 🌐
                                                                                            @stefano@mastodon.bsd.cafe

                                                                                            Next Saturday at 2026, I'll tell the story of one of the longest nights of my career.

                                                                                            On 10 March 2021, I had just fallen asleep when the alerts started arriving. One server down. Then another. And another.
                                                                                            Different servers, different workloads, one thing in common: the OVHcloud Strasbourg data centre.

                                                                                            Then came the news: SBG2 was on fire.

                                                                                            I had 142 servers there.

                                                                                            The mission for the night was simple to state: bring the critical services back before 8, then recover everything else as quickly as possible.

                                                                                            This talk is about what happened next. The things that worked, the architectural choices that saved us, and especially the ones that failed when we needed them most.

                                                                                            And it's also the story of why that night changed the way I design infrastructure, and why BSD systems became such an important part of it.

                                                                                            The night 142 of my servers went up in the clouds. Physically.

                                                                                            📅 Saturday 12 September, 11:15
                                                                                            📍 EuroBSDCon 2026, D.0.02

                                                                                            Cover slide for Stefano Marinelli’s EuroBSDCon 2026 presentation. A nighttime photo shows the OVHcloud Strasbourg data centre engulfed in flames and thick smoke. A huge orange "142" overlays the fire. Below, on a black background, the title reads: "The night 142 of my servers went up in the clouds. Physically." 
In the top-right corner: "Stefano Marinelli · EuroBSDCon 2026 · Saturday 12 September, 11:15 · D.0.02."

                                                                                            Alt...Cover slide for Stefano Marinelli’s EuroBSDCon 2026 presentation. A nighttime photo shows the OVHcloud Strasbourg data centre engulfed in flames and thick smoke. A huge orange "142" overlays the fire. Below, on a black background, the title reads: "The night 142 of my servers went up in the clouds. Physically." In the top-right corner: "Stefano Marinelli · EuroBSDCon 2026 · Saturday 12 September, 11:15 · D.0.02."

                                                                                              [?]Michael Dexter » 🌐
                                                                                              @dexter@bsd.network

                                                                                              Naive PkgBase buildworld question:

                                                                                              I assumed I could build world with only the FreeBSD-src package, but the build wants sys/sys/params.h

                                                                                              Is that all it needs and if so, should that live in the src (non-sys) package?

                                                                                                [?]BastilleBSD :freebsd: » 🌐
                                                                                                @BastilleBSD@fosstodon.org

                                                                                                Happy Friday

                                                                                                  [?]Pete Orrall [Pete/Pete] » 🌐
                                                                                                  @peteorrall@mastodon.bsd.cafe

                                                                                                  [?]Stefano Marinelli » 🌐
                                                                                                  @stefano@mastodon.bsd.cafe

                                                                                                  Beautiful post by @crocidb :

                                                                                                  This blog ran on Ubuntu 16.04 for 10 years. I migrated it to FreeBSD

                                                                                                  crocidb.com/post/this-blog-ran

                                                                                                    [?]𝙹𝚘𝚎𝚕 𝙲𝚊𝚛𝚗𝚊𝚝 ♑️🤪 » 🌐
                                                                                                    @joel@gts.tumfatig.net

                                                                                                    I still have not understood how to create an ephemeral / cronjob #FreeBSD #jail… The one that cron launches to run a (backup) script and which terminates itself with the script. They always end up in a half-broken state after the script terminates.

                                                                                                    So right now, I have a normal jail with nothing running in it (thank you persist;) and a crontab entry with a jexec call to the script.

                                                                                                    It seems to be working great. But I feel like this is a dirty hack.

                                                                                                      [?]Stefano Marinelli » 🌐
                                                                                                      @stefano@journal.bsd.cafe

                                                                                                      I’m Just the Barista

                                                                                                      The spirit of the BSD Cafe is to try to create a serene, open, friendly, positive, and welcoming environment for all who want to be a part of it. I am just the Barista. I can't solve the world's problems, but I can try to keep the counter clean, keep the machines running, serve a good BSD coffee, and ensure that, at least here, friends can find a moment of peace and constructive sharing. We need more bars and fewer shopping malls. [SENSITIVE CONTENT]

                                                                                                      This is the text I wrote for my part of the talk “Liberating the Social Web Using *BSD“, presented together with the great Jeroen (@h3artbl33d) at EuroBSDCon 2025 in Zagreb. It’s not a transcript – it’s the base I worked from, the thoughts I organized before stepping on stage. What I actually said may have been slightly different in places, as it always is when you speak from the heart rather than read from a page. But these are the words, and the spirit is exactly the same.

                                                                                                      Today, I’m not just here to talk about technology, but about how the principles of BSD systems can help us build healthier and more resilient online communities. And I’ll do this by telling you the story of the bar I founded, the BSD Cafe.

                                                                                                      The idea for the BSD Cafe was born long before its launch but, as I often do, I thought carefully about whether to proceed. On 27 December 2022, I decided to register the domain. The name came from careful reflection with my wife. The idea was to create a virtual space that resembled not so much the cafes scattered around the world, but the Italian “Cafe” (which are called “Bar”).

                                                                                                      For many years (and in many contexts, still today), Italian bars have been at the center of people’s recreational social lives. The Barista, the manager of the establishment, is not just a keeper but a point of reference: they don’t just serve coffee, but they listen and, if asked, offer advice with the wisdom of someone who sees many people and many things, even just out of the corner of their eye, and hears many stories. It used to be said that the best advisors were priests and bartenders, but that the latter certainly gave more entertaining advice.

                                                                                                      And the bar is precisely the place where people go to relax. There are often televisions, tables for playing cards, and recreational rooms. The bartender ensures that everything runs smoothly, but also that everyone feels comfortable: that the person passing through gets directions to their destination, that the person who just walked in gets their coffee at their preferred temperature, and that the person who entered a little earlier, who needs some rest today, has a table in a more private area.

                                                                                                      The spirit of the BSD Cafe is the same: to try to create a serene, open, friendly, positive, and welcoming environment for all who want to be a part of it. Those who just want to read can do so. Those who post a lot are welcome. Everyone should have the experience that makes them most comfortable and at ease. No one should ever feel forced to do something they don’t want to do; no one should ever feel uncomfortable. Therefore, everyone can choose a noisy and active table, or a more reserved and quiet one.

                                                                                                      We can therefore assume that the BSD Cafe has an infinite number of available tables. We can thus call it a Turing cafe. 🙂

                                                                                                      In Italian bars, people used to go (and in some areas, still do) to find their “bar friends”. These are people you meet at the bar without an appointment. You go to the bar freely, when you have the time and inclination, and you find the people who regularly frequent that place. And the choice of the bar often aligns with the theme of the bar itself. For example, in Italy, there are many “Bar Sports” where people meet to catch up, watch games together, and read and comment on sports news. The idea of the BSD Cafe is the same – a bar where enthusiasts of BSD systems, Open Source, and technology can be found. And for me, although I might occasionally talk about users (out of technical habit), at the BSD Cafe, there are only “bar friends”.

                                                                                                      The BSD Cafe is a place where we are “for”, not “against”. Supporters, not haters. Bar friends, not opponents. This doesn’t mean that opinions on other software can’t be expressed, even extremely negative ones (I do it myself from time to time), but the general spirit is that of open source: to build, to discuss, to understand. Wars against other solutions, especially if they are open source, are not part of the atmosphere of the BSD Cafe. We have our preferences – we support our ideas and solutions, but we are not here to “destroy” others. Among our users, there are people who develop Linux distributions – and for me, that is extremely positive!

                                                                                                      When people are at ease and in a serene environment, they are often encouraged to be serene themselves. Some are negative and aggressive because they absorb it from their environment. Some users of the BSD Cafe have told me exactly this: the civil, friendly, relaxed, positive, and constructive level of the BSD Cafe is good for their mental health. Conversely, there are unfortunately people who find pleasure in causing trouble, in muddying the atmosphere. For these people, unfortunately, there is no solution, but the Cafe is not the place for them.

                                                                                                      Political discussions can be part of our lives and daily routines, but the BSD Cafe is not a political group. In recent years, politics has become a topic not of discussion but of conflict. It has always been so to some extent, but commercial social media platforms have understood that hatred and conflict generate engagement, and engagement means selling advertising – a lot of advertising. Therefore, at the BSD Cafe, you might occasionally hear talk of politics or the political repercussions of technical decisions and choices. And that is perfectly okay. But it is not a place from which political conflicts should arise. We are for – supporters, not haters. We are here to build, not to destroy.

                                                                                                      The BSD Cafe is therefore a place centered on the BSDs, and all services are, therefore, based on BSD operating systems.

                                                                                                      All technologies used must be able to run “from my garage”. I am a professional – so this is not a hobby project – but it must not depend on any proprietary solution or “Cloud” solution. Today, there is a tendency to standardize (too much?) everything related to technical choices. If it’s pro, it’s Kubernetes/cloud/serverless/etc. – if it’s not, it’s “old” or “not pro”. I am, and have always been, a proponent of OwnYourData. And this is a mantra at the BSD Cafe. All services are based on Open Source solutions, outside the dynamics and centralized management of the usual companies. We must be free and maintain our technological autonomy; we cannot create a system where our communications and our data depend exclusively on third-party companies. I have enough experience to understand that, sooner or later, even the most solid companies can fail or change their business model. The BSD Cafe is therefore always in favor of self-hosting. Sometimes this means losing users, but not bar friends. It happens, in fact, that at a certain point, friends decide to try the BSDs and start self-hosting their own services. For me, that is a success: one less number in the statistics, but one more success on a technical and ideological level. And for all intents and purposes, they remain bar friends, even if their “handle” is different from “bsd.cafe” – it is the spirit, not an extension, that unites us.

                                                                                                      From time to time, I have migrated the main VM of the BSD Cafe. Sometimes I have given notice, other times not (the downtime is minimal). In some cases, the system has run from my home desk, from the Mini PC I used as a home server and now use daily as a workstation. At the core of the technical choices, in fact, is the decision not to depend (strictly) on any specific technology or hardware. For this reason, the structure of the BSD Cafe is replicable and malleable, as well as described in its Wiki: it is a community of technology enthusiasts, and I want them to judge the choices transparently and autonomously, without hiding anything.

                                                                                                      The BSD Cafe was not created to be just a Fediverse instance but, from the beginning, to provide a series of services powered by the BSDs for enthusiasts and friends of the BSDs. To date, the main services are:

                                                                                                      • A Mastodon instance – the beating heart of the BSD Cafe in the Fediverse, which currently has about 500 total users (now 600 – of which about half have been active in the last 30 days). This is where we chat, get informed, joke, critique, build, discuss, and get to know each other.
                                                                                                      • A snac instance – also for access to the Fediverse. Snac is an example of lightweight software, with no dependencies, that is stable and easy to self-host. It does not use a database but the file system and is the basis of another project of mine, FediMeteo. The snac/ZFS combination is fantastic. The developer is a caring, helpful, and fantastic person. It is my first choice for personal projects and more – it currently has more or less 30 users.
                                                                                                      • A Lemmy instance – blendit – which, however, is giving me problems and headaches. I’ve been thinking about it for a while; it might be the first of the BSD Cafe services that I will be forced to retire. More about this later.
                                                                                                      • A Matrix server – based on Synapse, it has become the hub for many interesting topics both in the thematic channels (BSD-themed) and in the Lounge, the general channel, where we talk about a bit of everything. The server is federated, so it is also an access point for channels and groups on other servers. We chat, we discuss, we ask – a bit like with the Fediverse, but on Matrix.
                                                                                                      • miniflux and freshrss – RSS is not dead – it is alive and well and still a fundamental tool for updates and consultation. Two jails, two services to give our friends a way to read the news. This is our reading corner, the newspapers, the newsletters. Here, you remain autonomous and in silence, you choose what you want to read, and you savor the content. Without advertising, without interruptions.
                                                                                                      • wallabag – called “press” – to save your bookmarks, sites, articles. Save the web. Freely. Our post-it notes, but private.
                                                                                                      • myip – by connecting to myip, you will get your IP back – both v4 and v6 – via telnet, http, https, ssh, etc. – ideally, it is an echo chamber, to “hear” the reflection of your own voice – that is, your own IP.
                                                                                                      • wiki.bsd.cafe – the project’s homepage and a series of articles and content about the BSDs. It is not very rich in content at the moment, but some friends contribute regularly and keep the information in it updated. It contains articles on how the BSD Cafe is structured (for each service, an explanation of the division into jails, etc.). Our recipe book – for the coffee machine, but also for the BSDs!
                                                                                                      • brew.bsd.cafe – powered by Forgejo, it has become the home for many projects by friends of the BSD Cafe. I use it daily for my own needs, and it is a way to avoid using centralized tools controlled by the “usual suspects”. And, unlike the main and most famous similar service in the world, it also supports IPv6! It is our creative workshop, the development den. The garage where we have our tools and build, collaborating.
                                                                                                      • journal.bsd.cafe – the latest, in chronological order, added to the BSD Cafe. Our journal, what we want to tell the world and leave a trace of. It is a WordPress blog, federated in the Fediverse thanks to the ActivityPub plugin, where authors can create and publish articles, even those not strictly related to the BSDs. So far, various articles have been published, and some of them have had some success on sites like Hacker News or Lobste.rs – because quality is still appreciated, especially in the world of standardized and imprecise content from LLMs (or “AI”, as is fashionable today).
                                                                                                      • There are other active services but not publicly usable, such as “tube” – our TV – Peertube. They are currently experimental.

                                                                                                      Let’s get into the technical details:

                                                                                                      The BSD Cafe is not “cloud ready”. The BSD Cafe was not created to be serverless. We love our servers, and we don’t need the “cloud” to run our services.

                                                                                                      The BSD Cafe started with a FreeBSD VM on Hetzner in Finland for €3.29 per month. It is still active and is the primary for the entire infrastructure and is named “bsdcafevm”. It hosts the reverse proxy, in a jail, which routes all incoming connections, and is the “router” for the larger VM. This VM also hosts a “ns2” jail, which is the secondary DNS, and the “backup” instance of Mastodon, which helps with queue management and becomes primary when I shut down the other one during updates. For IPv6, Hetzner assigns a routed /64 block. I have divided it into /72 subnets so that I can route to other VPSs, services, etc., and provide an IPv6 address to any jail.

                                                                                                      The main VPS, which hosts the services, called “bc01”, connects to this VM via Wireguard. bc01 has some particular characteristics, including:

                                                                                                      • It was originally a VM on Proxmox, as I was using hardware I already owned. It is now on bhyve, on a FreeBSD host under my control (in Germany).
                                                                                                      • It does not have a public IP assigned, but connects to the Internet only via NAT on the host. This is a clear choice: this VM should only connect to bsdcafevm. BSDCafeVM will forward connections from the reverse proxy and will handle “NATing” outgoing IPv4 connections from bc01. The Wireguard rules on BSDCafeVM will also ensure that IPv6 connections reach the jails of this VM. The purpose is simple: this VM must be able to be moved anywhere, and the services must be able to resume functioning immediately. And this happens because all it needs is a Wireguard connection to BSDCafeVM, so there are no services exposed directly. This is the reason why this VM has been moved many times without any changes to IPs, addresses, etc. More information on this VM later.

                                                                                                      A small VM (for one euro per month) based on FreeBSD that, within a jail, has the ns1 nameserver, which is the primary authoritative one. This VM also serves other purposes from time to time, such as monitoring the rest, etc.

                                                                                                      A jail within one of my FreeBSD hosts in Poland, on OVH, contains the media files for the Mastodon instance. This is the most voluminous part of the entire hosting setup because Mastodon downloads and reprocesses all the multimedia content it encounters. This is for two main purposes: to clean it, in order to possibly remove malicious content, and to ensure that users of one’s own instance only have contact with their own media repository, not with that of the original instance – both for performance and privacy reasons. This server has spinning disks. Initially, I used Minio, but over time, performance plummeted. A few months ago, I migrated to SeaweedFS, and I am very satisfied with it. The outgoing bandwidth of this machine is not very wide, and I have other services on it. For this reason, I applied a solution that I described in an article on my blog.

                                                                                                      I have used some VMs or physical hosts (spread across Europe and the USA) to act as a CDN. The BSD Cafe’s DNS will return the IP (both v4 and v6) closest to the caller, among those available, and this host will connect directly to the media server, then caching the content. The problem, in fact, does not arise when a user scrolls through their timeline, but as soon as they publish multimedia content: all known instances will connect to download and reprocess that file, generating a spike. This has little impact if it is a normal post, but it is extremely voluminous if it is content of a considerable size, like an image or a video. In this way, the various CDN nodes will download the content only once and serve it to all instances in their area of competence. These CDN nodes also do other things, can be activated or deactivated based on my needs, and are based on FreeBSD, NetBSD, and OpenBSD (one of them is on OpenBSD Amsterdam).

                                                                                                      Another FreeBSD VPS (which I use for other things) contains “status.bsd.cafe“, which is the jail with Uptime Kuma that shows the status of the services or any of my communications about them. I do not receive notifications from this host, but from another monitoring system, so it is only to show the status of the situation.

                                                                                                      In practice, the BSD Cafe mainly needs the “endpoint” VPS, the VPS with the services, and the jail with the media, which could be condensed into a single system if desired. Everything else is optional and I keep it active as I have resources available on external hardware.

                                                                                                      Many of the technical choices have been documented in articles on my blog or in the BSD Cafe Wiki.

                                                                                                      But all of this requires backups. And the BSD Cafe has a clear and defined backup procedure.

                                                                                                      The main VPSs – namely bsdcafevm and bc01 – are based on FreeBSD and, therefore, ZFS. Both have the same type of backup, defined as follows:

                                                                                                      • A local snapshot every 5 minutes, kept for two hours. In this way, in case of problems, it is possible to “clean up the coffee drop” before the tablecloth is indelibly stained—as well as one per hour, kept for 24 hours.
                                                                                                      • An external backup, performed at regular intervals, to an external backup host. The frequency varies from 15 minutes to an hour, depending on the available space and the load, which I modify according to my needs. All datasets of the VMs are copied, including system ones, for a possible quick recovery in case of a disaster.
                                                                                                      • An external backup to a backup server of mine, one meter away from me. This happens every 24 hours, and I consider it the “extreme disaster recovery” because, in my opinion, the safest data is the data that is physically reachable. The disks of this server (which also contains other backups) are all encrypted with GELI, so in case of theft, they are unusable.

                                                                                                      Last but not least, the physical FreeBSD host on which bc01 currently rests is also backed up every 15 minutes to another external backup server, so the entire disk image. An additional layer of redundancy, to help me sleep better at night.

                                                                                                      From a technical standpoint, therefore, I have tried to create a simple but secure infrastructure, with the most granular separation possible (for example: the main Mastodon instance has a jail for Mastodon, one for the Redis for the queues, etc., one for the Redis for the timeline caches (only in RAM, does not write to disk), and one for the database (PostgreSQL).

                                                                                                      Then there are the common service jails (unbound for DNS resolutions, smtp for sending and receiving emails, etc.).

                                                                                                      Being the Barista of the BSD Cafe is a privilege and an honor. The success of the project has exceeded my expectations, and this has filled me with joy. The BSD community is fantastic, mature, intelligent, and positive. The friends who approach the BSDs absorb all of this and transmit it to others, creating a virtuous circle. But it’s not always roses. There are problems, from time to time, that need to be solved. And, to quote my previous talk: “The main challenge is often ideological, not technical“.

                                                                                                      Apart from the problems with blendit – Lemmy – which accumulates all the media it sees in a frenzied way and never deletes it, as well as having created serious update problems – all the software is on average stable and reliable.

                                                                                                      The most complex part of my role as a barista, in fact, is not technical, but human: moderation. The techniques of scams and disturbances are constantly improving, and it is increasingly difficult to distinguish a new friend of the bar from a troublemaker. But the biggest challenge is maintaining balance.

                                                                                                      Our philosophy is clear: to be for, not against. Supporters, not haters. This principle is a conscious choice, in stark contrast to the dominant model of commercial social media. These platforms are often designed around an engagement economy, where algorithms optimized to generate conflict and outrage maximize the time spent on the site and, consequently, advertising profits. The BSD Cafe rejects this model. We are not here to capitalize on anger, but to build a refuge from the toxicity of the internet.

                                                                                                      This approach manifests itself in the way we handle controversial topics. Recently, a technical theme with strong political implications has begun to appear in discussions. My line is not to censor the topic itself. I firmly believe in open discussion. I only intervene when the discussion ceases to be a critical analysis and becomes a personal attack. For some, this is not enough: they would like a total ban on certain topics and the immediate exclusion of those who introduce them. My experience, however, has shown me that a more patient approach is often more constructive. I have seen people support controversial software solutions simply because they did not know their background. Thanks to civil and informative discussions, they have understood the context, thanked the community, and made more informed choices. Banning them instantly would have been unfair and would have denied everyone an opportunity for growth.

                                                                                                      However, this philosophy of constructive positivity has attracted a specific criticism: that of promoting “Toxic Positivity”. The accusation is that, in our desire to maintain a serene environment, we end up excluding those who are suffering, invalidating their negative experiences because they “clash” with the atmosphere of the bar.

                                                                                                      This is a criticism that I take very seriously, because it touches the heart of the project. And my answer is that it is a fundamental misunderstanding of our purpose. The goal is not to deny that pain, injustice, and suffering exist in the world. On the contrary: the BSD Cafe exists precisely because the world is often a difficult place.

                                                                                                      Our purpose is not to pretend that those who suffer should stop suffering, but to offer them a place where, for a while, they may not be defined solely by their suffering. A place where they can be, first and foremost, a technology enthusiast, a FreeBSD expert, a curious OpenBSD user. A friend of the bar. We are always ready to support, console, and help those who need it, but we want to protect that mental space where shared passions unite us and give us relief.

                                                                                                      Fortunately, this vision is confirmed by the very people we are trying to help. The number of private messages of appreciation I receive from people going through terrible times far exceeds the criticism. They write to me that “the civil, friendly, and constructive level of the BSD Cafe is good for their mental health”, because it allows them to disconnect from daily dramas that would otherwise be unbearable.

                                                                                                      I am just the Barista. I can’t solve the world’s problems, but I can try to keep the counter clean, keep the machines running, serve a good (BSD) coffee, distribute (many) stickers, and ensure that, at least here, friends can find a moment of peace and constructive sharing. But a bar is nothing without its regulars. And the success of the BSD Cafe is not mine, but that of the BSD Community and the friends who are part of it. The richness of this place is not only the quality of the Coffee (which, being BSD, is very high), but mainly the human richness of the friends who are part of it. And to them, to all of you, I say thank you. From the bottom of my heart.

                                                                                                      We need more bars and fewer shopping malls, and that is why I recently also founded the illumos Cafe. We want people who sit down, who socialize, or who simply enjoy the atmosphere of an environment that is familiar, friendly, and positive to them. Like this conference and all the BSD Conferences, because the environment is the same. Enough of shiny shop windows; a good hot drink, in the company of friends, can help you live better. “From the people, for the people“.

                                                                                                      Me, presenting a slide

                                                                                                      Alt...Me, presenting a slide

                                                                                                      [?]Stefano Marinelli » 🌐
                                                                                                      @stefano@mastodon.bsd.cafe

                                                                                                      One of today’s tasks: migrating an old Ubuntu server hosting around 15 WordPress sites to a FreeBSD server, with Caddy acting as a reverse proxy in its own jail, one jail per WordPress instance, and a shared database in yet another jail.

                                                                                                      Yesterday I configured Caddy to reverse proxy all the domains while still pointing to the old server. That allowed the customer to update the DNS records in advance, while I could migrate each site one by one and simply switch the upstream in Caddy as soon as it was ready.

                                                                                                      Zero downtime. Just a reload.

                                                                                                      I asked only for one thing: freeze everything this morning, so a colleague asked the customer not to make any changes to the websites after 7 today.

                                                                                                      Ack.

                                                                                                      So I go to clone one of the sites… and notice the customer published a totally deferrable post at 9.

                                                                                                      Which, of course, means I now get to resync everything.

                                                                                                      Ah, the joys of working "behind the scenes". 😆

                                                                                                        [?]FreeBSD Foundation » 🌐
                                                                                                        @FreeBSDFoundation@mastodon.social

                                                                                                        Join Tuukka Pasanen today for our next Lunch & Learn as he explores the work underway to transition the FreeBSD Vulnerability Database from VuXML to OSV, a widely used vulnerability format that officially supports FreeBSD in its schema.

                                                                                                        📅 Wednesday, September 2 | 11:00 AM CDT / 16:00 UTC
                                                                                                        Speaker: Tuukka Pasanen | FreeBSD Foundation Lunch & Learn

                                                                                                        YouTube Live Link:
                                                                                                        buff.ly/m5XZp1S

                                                                                                          [?]Tom [he/him they/them] » 🌐
                                                                                                          @pertho@mastodon.bsd.cafe

                                                                                                          Anyone running and (DNS resolver) and finding unbound doesn't actually start after a reboot?

                                                                                                          The init script has:

                                                                                                          # PROVIDE: unbound
                                                                                                          # REQUIRE: FILESYSTEMS defaultroute netwait resolv
                                                                                                          # BEFORE: NETWORKING
                                                                                                          # KEYWORD: shutdown

                                                                                                          However, unbound needs to listen on an interface or IP. Why have the script run before networking and yet "require" defaultroute? This makes no sense.

                                                                                                            [?]FreeBSD Foundation » 🌐
                                                                                                            @FreeBSDFoundation@mastodon.social

                                                                                                            Join Klara's Allan Jude and FreeBSD Security Officer Gordon Tetlow for a technical webinar on securing production FreeBSD systems. Klara Inc

                                                                                                            In this session, you'll learn about FreeBSD's security features, best practices for securing production environments, how the FreeBSD Security Team responds to vulnerabilities and publishes security advisories, and common operational mistakes that can increase risk.

                                                                                                            📅 September 2, 2026
                                                                                                            🕚 11:00 AM EDT

                                                                                                            Register here: klarasystems.com/webinars/free

                                                                                                              [?]BastilleBSD :freebsd: » 🌐
                                                                                                              @BastilleBSD@fosstodon.org

                                                                                                              Monthly reminder to periodically check your bastille.conf for updates or new entries from the sample config:

                                                                                                              cd /usr/local/etc/bastille
                                                                                                              diff -u bastille.conf bastille.conf.sample

                                                                                                              We try to keep config updates to a minimum, but sometimes they are required.

                                                                                                                [?]Tom [he/him they/them] » 🌐
                                                                                                                @pertho@mastodon.bsd.cafe

                                                                                                                Hey folks: If I do NOT have a /64 assigned to me and only have a single IPv6 assigned, am I better off adding fd00::/7 addresses to the jails and then NAT'ing to them like I do with the IPv4 addresses?

                                                                                                                I don't think I have any other kind of choice here.

                                                                                                                  [?]Jan » 🌐
                                                                                                                  @js@mastodon.bsd.cafe

                                                                                                                  Thanks everyone for helping me find the right hardware!

                                                                                                                  I went with a T640, two Intel Xeon Gold 6248R, 192GB ram, 10gbit sfp+ networking, HBA330 and redundant 1100W PSUs.

                                                                                                                  It's not the newest hardware out there, but the spare parts are cheap enough and it has more than enough power for my needs.

                                                                                                                  Jails, VMs, Storage (if there is need for more than 8x3.5 HDDs, I'll go JBOD).

                                                                                                                  I'll update as soon as I have put everything together and moved over all VMs, storage and jails. It'll be great to free up one Lenovo m75q Gen5, one Lenovo 720q and to decommission the "old" N100 32GB RAM NAS hardware (a friend will most likely take it).

                                                                                                                    [?]Jan » 🌐
                                                                                                                    @js@mastodon.bsd.cafe

                                                                                                                    I did build >1500 FreeBSD packages until I noticed that HT was disabled.

                                                                                                                    Machine was only using 48 instead of 96 cores.

                                                                                                                      [?]Jan » 🌐
                                                                                                                      @js@mastodon.bsd.cafe

                                                                                                                      With me building a lot of packages my tool to trigger single package builds via a web interface is now resurrected.

                                                                                                                      Don't worry, the one job it has is to trigger poudriere builds and have queue that triggers the next job in case a worker is running.

                                                                                                                      I'm a simple man and I used for that.

                                                                                                                        [?]Jan » 🌐
                                                                                                                        @js@mastodon.bsd.cafe

                                                                                                                        Before you ask: Yes, it can (if you choose to) persist the selected package to the default build that gets triggered every night).

                                                                                                                          [?] » 🌐
                                                                                                                          @grahamperrin@mastodon.bsd.cafe

                                                                                                                          BSDnas

                                                                                                                          github.com/bsdnas

                                                                                                                          ― a community fork of TrueNAS CORE, kept on a FreeBSD that still gets security fixes.

                                                                                                                          reddit.com/r/freebsd/comments/

                                                                                                                            [?]vermaden » 🌐
                                                                                                                            @vermaden@mastodon.bsd.cafe

                                                                                                                            Latest 𝗩𝗮𝗹𝘂𝗮𝗯𝗹𝗲 𝗡𝗲𝘄𝘀 - 𝟮𝟬𝟮𝟲/𝟬𝟴/𝟯𝟭 (Valuable News - 2026/08/31) available.

                                                                                                                            vermaden.wordpress.com/2026/08

                                                                                                                            Past releases: vermaden.wordpress.com/news/

                                                                                                                              [?]EuroBSDCon » 🌐
                                                                                                                              @EuroBSDCon@bsd.network

                                                                                                                              We are counting down to the European *BSD event of the year! 😈⛳🐡

                                                                                                                              Big thank you to our silver sponsor: FreeBSD Foundation
                                                                                                                              freebsdfoundation.org/

                                                                                                                              If you haven't secured your spot yet, now's the time!
                                                                                                                              tickets.eurobsdcon.org/

                                                                                                                              📅 You can check out the program at events.eurobsdcon.org/2026/sch

                                                                                                                              EuroBSDCon 2026 in Brussels, Belgium 🇧🇪
                                                                                                                              September 09-13, 2026

                                                                                                                                [?]Tim Chase » 🌐
                                                                                                                                @gumnos@mastodon.bsd.cafe

                                                                                                                                some days I wish upgrading was as mindless as upgrading my machines.

                                                                                                                                On OpenBSD, it's generally `sysupgrade`, let it do its thing, rebooting itself a couple times (entering my FDE passwords as necessary), and then a `pkg_add -u` to upgrade my packages. Sometimes a `sysmerge` if it can't do it automatically. But very much two (or three) idiot-proof commands with very little demand on this idiot's brain to recall where I am in the process.

                                                                                                                                While I like the automatic ZFS boot-environment snapshotting, FreeBSD requires me to know the next version-number I want to upgrade to (can't determine it or prompt me for viable options?), transcribe it as part of the upgrade command, then manually running `freebsd-update install` multiple times, rebooting manually multiple times between each, then `pkg update` and a `pkg upgrade` to update userspace. I'm sitting at a login…is this the first, second, or third reboot? I don't know, it was taking a while and I ended up wandering off to do something else.

                                                                                                                                This post brought to you by this morning's 14.3→14.4 FreeBSD upgrade 😆

                                                                                                                                  It's Just Me boosted

                                                                                                                                  [?]Stefano Marinelli » 🌐
                                                                                                                                  @stefano@mastodon.bsd.cafe

                                                                                                                                  EDIT: the recording is available here: exquisite.tube/w/nQbc54t4G7YGa

                                                                                                                                  On 10 March 2021, I had only just fallen asleep when my phone started buzzing. Then another notification, and another. In a matter of minutes, 142 of my servers went up in the clouds. And not the cloud-computing kind.

                                                                                                                                  Most of them were physically going up in a column of smoke in Strasbourg.

                                                                                                                                  My wife looked at me and asked if I wanted a coffee. I nodded. It was going to be a very long day.

                                                                                                                                  At EuroBSDCon 2026, I won't be giving a theoretical lecture on high availability. Instead, I’m going to tell the raw story of that night: the emergency recovery, the architectural choices that actually saved us, and the ones that crumbled under pressure (because we rarely talk about what fails).

                                                                                                                                  Most of all, I’ll explain why that night changed my perspective, and why I’ve come to see BSD systems not just as operating systems, but as essential, practical tools for building simpler, more resilient infrastructure.

                                                                                                                                  The official schedule is now live. If you want to hear a real-world post-mortem, join me on Saturday, 12 Sept at 11:15 (Room D.0.02).

                                                                                                                                  EuroBSDCon Full schedule: events.eurobsdcon.org/2026/sch
                                                                                                                                  See you there! ☕️

                                                                                                                                    [?]Stefano Marinelli » 🌐
                                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                                    Great news! My presentation for has been accepted!

                                                                                                                                    Expect a mix of disasters, horror stories, recoveries, BSDs, and one very, very long day.

                                                                                                                                    Stay tuned!

                                                                                                                                      [?]Stefano Marinelli » 🌐
                                                                                                                                      @stefano@mastodon.bsd.cafe

                                                                                                                                      Coming next week: a post about the FediMeteo bot, how it works, how it has evolved, and the overall structure of jails. The following week: caching the BSD Cafe Mastodon instances on nginx.

                                                                                                                                      Stay tuned on ITNotes!

                                                                                                                                        [?]IT Notes - https://it-notes.dragas.net » 🤖 🌐
                                                                                                                                        @itnotes@snac.it-notes.dragas.net

                                                                                                                                        FediMeteo, HAProxy, and the art of not wasting snac threads

                                                                                                                                        When I wrote about FediMeteo (https://it-notes.dragas.net/2025/02/26/fedimeteo-how-a-tiny-freebsd-vps-became-a-global-weather-service-for-thousands/) for the first time, I told the story from the beginning: the idea born almost by chance while checking the weather for a holiday, the memory of my grandfather, who for years had been my personal meteorologist, the decision to build something small and useful, and then the surprise of seeing people actually use it. What began as a personal experiment quickly became a small global service, still running with the same philosophy: FreeBSD, jails, simple scripts, snac, text, emoji, and a lot of small pieces doing their work quietly.

                                                                                                                                        That article was mostly about the birth and growth of the project. This one is about one of the less romantic parts of the same story, although I have to admit that I find a certain beauty in it too: keeping the service light as it grows.

                                                                                                                                        FediMeteo (https://fedimeteo.com) is still intentionally simple from the outside. A homepage, some numbers, a list of countries, and many ActivityPub accounts publishing weather forecasts. The posts are text and emoji. There is no JavaScript requirement to read the pages, no heavy frontend, no unnecessary media attached to every forecast, and no dynamic homepage recalculated at every visit just to show the same numbers. This is not accidental. It is the way I wanted the service to behave from the beginning.

                                                                                                                                        But the more the service is used, the more the small details matter. A request that looks harmless when there are ten followers may become a repeated request when there are thousands of followers, remote instances, crawlers, previews, and other servers fetching the same public objects. In the Fediverse, the same small thing can be asked many times by many different places, each one with a perfectly legitimate reason. The backend doesn't care: it just needs to deal with the requests.

                                                                                                                                        And in FediMeteo, the backend is snac (https://codeberg.org/grunfink/snac2).

                                                                                                                                        I like snac very much precisely because it is small, clear, and efficient. It is not a giant application that tries to be everything. It does a focused job and does it well. But this also means that I want to respect its shape. I do not want to waste its threads on work that the reverse proxy can safely do. A snac thread serving the same public avatar again and again is not a tragedy, but it is still a waste. A snac thread answering the same public ActivityPub object several times in the same minute is doing real work, but often not necessary work.

                                                                                                                                        This is the reason behind the HAProxy (https://www.haproxy.org) tuning I am currently using in front of FediMeteo.

                                                                                                                                        It is not about making the configuration look clever. It is about keeping snac quiet.

                                                                                                                                        A continuation of the same idea

                                                                                                                                        I had already explored the same problem with snac and nginx in two previous posts: Improving snac Performance with Nginx Proxy Cache (https://it-notes.dragas.net/2025/01/29/improving-snac-performance-with-nginx-proxy-cache/) and Caching snac Proxied Media with Nginx (https://it-notes.dragas.net/2025/02/08/caching-snac-proxied-media-with-nginx/). In both cases, the idea was that the reverse proxy should absorb repeated public requests instead of letting them consume snac resources.

                                                                                                                                        This is especially important because snac uses a limited number of threads. I like that. Limits are healthy. They force us to understand what the service is doing, and they prevent a small program from pretending to be an infinite resource. But limits also make waste visible. If a few threads are busy serving files that could have been served from cache, those threads are not available for something more useful.

                                                                                                                                        With FediMeteo the implementation is different because the reverse proxy is HAProxy, but the reasoning is the same. I have many small snac instances, each one in its own FreeBSD (Bastille (https://github.com/BastilleBSD/bastille)) jail, and one public entry point that has to route, terminate TLS, compress, cache, and generally remove as much repetitive work as possible from the backends.

                                                                                                                                        This is, in a way, the natural continuation of the original FediMeteo design. In the first article I wrote that I wanted to manage everything according to the Unix philosophy: small pieces working together. This is another piece of that same puzzle. HAProxy does the edge work. snac does the ActivityPub work. Scripts generate forecasts. cron launches updates. ZFS gives me snapshots. FreeBSD jails keep countries separated. Nothing is particularly heroic by itself, but the whole system becomes pleasant because each part has a clear responsibility.

                                                                                                                                        Why there is almost no media

                                                                                                                                        Before talking about HAProxy, it is worth mentioning one of the most important optimizations, which is not in the proxy configuration at all.

                                                                                                                                        FediMeteo does not use media in its forecasts.

                                                                                                                                        No images attached to the posts, no generated weather cards, no maps for each city, no decorative banners. The forecasts are text and emoji. This was a deliberate decision. Weather information does not become more useful just because it is put inside an image, and every media file used by the service would become something to store, serve, cache, federate, expire, back up, and occasionally debug.

                                                                                                                                        Text and emoji are enough. They are accessible, light, readable in text browsers, friendly to timelines, and understandable even when someone does not know the local language perfectly. This was one of the original design principles of FediMeteo, and it also helps the infrastructure. Less media means less work, fewer cache entries, fewer repeated fetches, fewer surprises.

                                                                                                                                        There is one exception: the avatar.

                                                                                                                                        All FediMeteo accounts use the same avatar, and this is also intentional. I could have used a different avatar for each country, or for each city, or created something visually richer. It would have been nicer in some screenshots, perhaps. It would also have been operationally worse.

                                                                                                                                        With one shared avatar, the reverse proxy has one very useful object to cache. It is public, identical for everyone, small, requested often, and therefore almost always hot in cache. HAProxy can serve it directly instead of asking each snac instance to return the same file. Since avatars are requested by remote instances, browsers, profile previews, and all sorts of federation-related fetches, this single decision removes a surprising amount of pointless backend traffic.

                                                                                                                                        So the avatar is not only a visual identity. It is part of the architecture.

                                                                                                                                        This is the kind of optimization I like most, because it starts before the software. It starts with deciding not to create a problem.

                                                                                                                                        The homepage is static because it can be static

                                                                                                                                        The main homepage follows the same logic.

                                                                                                                                        It is a static HTML page generated from a template. Once per hour, a cron script updates the numbers and statistics. It counts the data I want to show, regenerates the page, and then the page remains static until the next run.

                                                                                                                                        This is not because I cannot make a dynamic page. It is because I do not need one. Boring is good.

                                                                                                                                        The homepage does not need to query all the country instances on every visit. It does not need a database request for each user who opens it. It does not need to ask snac anything in real time. The numbers are useful, but they do not need to be updated every second. Once per hour is enough, and it also fits the spirit of the whole project: do the work when it is needed, then serve the result cheaply.

                                                                                                                                        I have seen too many small services become heavy because the first implementation was convenient rather than appropriate. A cron job and a template are not fashionable, but they are often exactly what a page like this needs.

                                                                                                                                        Many countries, one entry point

                                                                                                                                        FediMeteo is made of many country instances. Each one runs in its own jail and listens on its own internal address and port. From the outside, however, they all live under the same domain structure:

                                                                                                                                        fedimeteo.com
                                                                                                                                        www.fedimeteo.com
                                                                                                                                        it.fedimeteo.com
                                                                                                                                        uk.fedimeteo.com
                                                                                                                                        jp.fedimeteo.com
                                                                                                                                        us.fedimeteo.com
                                                                                                                                        usa.fedimeteo.com
                                                                                                                                        can.fedimeteo.com
                                                                                                                                        canada.fedimeteo.com
                                                                                                                                        And many more.

                                                                                                                                        At the beginning, it is always tempting to write one ACL after another in the HAProxy frontend. It is quick, it is explicit, and for five hostnames it is perfectly fine. But FediMeteo did not remain at five hostnames. As countries and aliases grew, a long chain of ACLs would have turned the frontend into a list of names instead of a description of how the proxy behaves.

                                                                                                                                        So I moved the hostname to backend mapping into a map file:

                                                                                                                                        fedimeteo.com        backend_fedimeteo
                                                                                                                                        www.fedimeteo.com backend_fedimeteo
                                                                                                                                        it.fedimeteo.com backend_it
                                                                                                                                        uk.fedimeteo.com backend_uk
                                                                                                                                        jp.fedimeteo.com backend_jp
                                                                                                                                        us.fedimeteo.com backend_us
                                                                                                                                        usa.fedimeteo.com backend_us
                                                                                                                                        can.fedimeteo.com backend_ca
                                                                                                                                        canada.fedimeteo.com backend_ca
                                                                                                                                        The frontend then needs only one rule:

                                                                                                                                        use_backend %[req.hdr(host),field(1,:),lower,map(/usr/local/etc/fedimeteo.map,backend_fedimeteo)]
                                                                                                                                        This reads the Host header, removes the port if present, lowercases the result, and looks it up in /usr/local/etc/fedimeteo.map. If nothing matches, it falls back to the main FediMeteo backend.

                                                                                                                                        I like this because it keeps the configuration honest. The frontend contains the policy. The map contains the data. Adding a country means adding an entry to the map and defining a backend. I do not need to make the frontend more complicated every time the service grows.

                                                                                                                                        Backends as small compartments

                                                                                                                                        The country backends are deliberately plain:

                                                                                                                                        backend backend_it
                                                                                                                                        mode http
                                                                                                                                        http-reuse safe
                                                                                                                                        server srv1 10.0.0.2:8001 maxconn 30

                                                                                                                                        backend backend_uk
                                                                                                                                        mode http
                                                                                                                                        http-reuse safe
                                                                                                                                        server srv1 10.0.0.7:8001 maxconn 30

                                                                                                                                        backend backend_jp
                                                                                                                                        mode http
                                                                                                                                        http-reuse safe
                                                                                                                                        server srv1 10.0.0.32:8001 maxconn 30

                                                                                                                                        One backend, one jail, one snac instance. This is exactly the same organizational principle as the rest of the project. If I need to reason about Italy, I look at the Italian jail. If I need to reason about the United Kingdom, I look at the UK jail. If one day I need to move a country elsewhere, the separation is already there.

                                                                                                                                        The maxconn 30 value is not a magic number. It is a ceiling. I want each small backend to have a visible limit in front of it. If something starts hammering a country instance, I prefer the pressure to appear at the HAProxy layer instead of becoming unlimited concurrent work inside snac.

                                                                                                                                        http-reuse safe lets HAProxy reuse backend connections where appropriate. This is another small reduction in unnecessary work. Opening connections repeatedly is not the biggest problem in the world, but avoiding it is still better, especially when many small services sit behind the same proxy.

                                                                                                                                        The front door

                                                                                                                                        The HTTPS frontend listens on IPv4 and IPv6 and offers both HTTP/2 and HTTP/1.1:

                                                                                                                                        frontend https_in
                                                                                                                                        bind :::443 v4v6 ssl crt /usr/local/etc/certs/ alpn h2,http/1.1
                                                                                                                                        mode http
                                                                                                                                        option http-keep-alive
                                                                                                                                        TLS defaults are set globally:

                                                                                                                                        ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
                                                                                                                                        ssl-default-bind-options no-sslv3 no-tlsv10 no-tlsv11 no-tls-tickets
                                                                                                                                        Port 80 only redirects to HTTPS, except for Let's Encrypt challenges:

                                                                                                                                        acl letsencrypt-acl path_beg /.well-known/acme-challenge/
                                                                                                                                        http-request redirect scheme https code 301 unless letsencrypt-acl
                                                                                                                                        use_backend letsencrypt-backend if letsencrypt-acl
                                                                                                                                        In the HTTPS frontend I also set the usual forwarding headers:

                                                                                                                                        http-request set-header X-Real-IP %[src]
                                                                                                                                        http-request set-header X-Forwarded-Proto https
                                                                                                                                        And I add HSTS:

                                                                                                                                        http-response set-header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
                                                                                                                                        None of this is unusual, and that is fine. The interesting parts of an infrastructure are not always the parts that should be unusual.

                                                                                                                                        Two caches, because the requests are different

                                                                                                                                        The HAProxy configuration defines two caches:

                                                                                                                                        cache mediacache
                                                                                                                                        total-max-size 128
                                                                                                                                        max-object-size 10000000
                                                                                                                                        max-age 3600
                                                                                                                                        process-vary on
                                                                                                                                        max-secondary-entries 12

                                                                                                                                        cache jsoncache
                                                                                                                                        total-max-size 16
                                                                                                                                        max-object-size 1000000
                                                                                                                                        max-age 60
                                                                                                                                        process-vary on
                                                                                                                                        max-secondary-entries 12

                                                                                                                                        I keep media and ActivityPub JSON separate because they are not the same kind of traffic.

                                                                                                                                        The media cache is larger and has a longer maximum age. In FediMeteo, this mostly means the shared avatar and a few static-looking objects. Since there is intentionally almost no media, the important cached object is requested very often and remains warm.

                                                                                                                                        The JSON cache is smaller and short-lived. It is there for public ActivityPub GET requests, not to store federation state forever. A 60 second cache is enough to collapse many repeated requests that arrive close together in time, without pretending that ActivityPub responses should be treated like immutable files.

                                                                                                                                        This distinction is important. Caching is not one decision. It is a set of small decisions about what a response means, who can see it, how often it changes, and what happens if it is served again.

                                                                                                                                        Recognizing media

                                                                                                                                        For media, the ACL is based on file extensions:

                                                                                                                                        acl is_media path_end -i .jpg .jpeg .png .gif .webp .svg .ico .mp4 .webm .mp3 .ogg .wav .flac .mov .avi .mkv .m4v
                                                                                                                                        Then I store the result in a transaction variable:

                                                                                                                                        http-request set-var(txn.is_media) bool(true) if is_media
                                                                                                                                        The cache lookup is straightforward:

                                                                                                                                        http-request cache-use mediacache if { var(txn.is_media) -m bool true }
                                                                                                                                        And on the response side:

                                                                                                                                        http-response set-header Cache-Control "max-age=3600, public" if { var(txn.is_media) -m bool true }
                                                                                                                                        http-response del-header Set-Cookie if { var(txn.is_media) -m bool true }
                                                                                                                                        http-response del-header Vary if { var(txn.is_media) -m bool true }
                                                                                                                                        http-response cache-store mediacache if { var(txn.is_media) -m bool true }
                                                                                                                                        The Cache-Control header makes the intent explicit. Set-Cookie is removed because a public media object should not carry session information. Vary is removed because I do not want the same avatar to fragment into many cache entries because of harmless header differences.

                                                                                                                                        This is aggressive only if removed from its context. In this service, with this media policy, it is a reasonable choice. FediMeteo is not serving private media under these paths. It is mostly serving the same public avatar over and over.

                                                                                                                                        For the same reason, I clean the request before it reaches the backend:

                                                                                                                                        http-request del-header Authorization if { var(txn.is_media) -m bool true }
                                                                                                                                        http-request del-header Cookie if { var(txn.is_media) -m bool true }
                                                                                                                                        I would not do this globally. I do it after deciding that the request is media. Scope is what makes these rules safe.

                                                                                                                                        The result is exactly what I want: the shared avatar becomes an almost perfect cache object. Small, public, repeatedly requested, and served by HAProxy instead of snac.

                                                                                                                                        ActivityPub JSON microcaching

                                                                                                                                        The ActivityPub side starts from the Accept header:

                                                                                                                                        acl is_ap_json   req.hdr(Accept),lower -m sub application/activity+json
                                                                                                                                        acl is_ap_ldjson req.hdr(Accept),lower -m sub application/ld+json
                                                                                                                                        acl is_outbox path_end /outbox
                                                                                                                                        acl is_get method GET
                                                                                                                                        acl has_auth req.hdr(Authorization) -m found
                                                                                                                                        acl has_cookie req.hdr(Cookie) -m found
                                                                                                                                        This part matters because ActivityPub uses content negotiation. The same path may return HTML to a browser and JSON to a remote instance. If the proxy pretends that a URL is always one thing, it will eventually cache the wrong representation.

                                                                                                                                        So I only mark public ActivityPub GET requests as cacheable:

                                                                                                                                        http-request set-var(txn.is_activitypub) bool(true) if is_get !is_outbox is_ap_json !has_auth !has_cookie
                                                                                                                                        http-request set-var(txn.is_activitypub) bool(true) if is_get !is_outbox is_ap_ldjson !has_auth !has_cookie
                                                                                                                                        There are several decisions here, all important.

                                                                                                                                        It must be a GET, because I am not caching deliveries or anything that changes state. It must not be /outbox, because outbox collections are not the traffic I want to cache here. It must not have Authorization, and it must not have cookies, because authenticated or user-specific requests do not belong in a shared public cache.

                                                                                                                                        Then the cache can be used and populated:

                                                                                                                                        http-request cache-use jsoncache if { var(txn.is_activitypub) -m bool true }

                                                                                                                                        http-response set-header Cache-Control "max-age=60, public" if { var(txn.is_activitypub) -m bool true }
                                                                                                                                        http-response cache-store jsoncache if { var(txn.is_activitypub) -m bool true }

                                                                                                                                        Sixty seconds is short, but useful. Federation often creates small clusters of identical requests. A remote server fetches an actor, another fetches the same actor, something asks for the same object, something retries. I do not need to cache these responses for hours. I only need HAProxy to answer the second and third identical request during the same small burst.

                                                                                                                                        This is microcaching in the most practical sense. It reduces repeated work without changing the nature of the service.

                                                                                                                                        Static media paths

                                                                                                                                        There is also a rule for static paths:

                                                                                                                                        acl is_short_path path_reg ^/[^/]+/s/
                                                                                                                                        http-request cache-use mediacache if is_short_path
                                                                                                                                        This comes from the same observation that led me to cache snac media with nginx. snac uses static media paths, and those paths often represent the kind of public, repeatable traffic that should not consume backend threads if the proxy can serve it. I call them "short", not because they are, but because the first time I saw them, I thought the 's' stood for "short", not "static". The name just stuck.

                                                                                                                                        In FediMeteo this is less central than on a normal social instance, because I deliberately do not use media except for the avatar and basic static objects. Still, the rule fits the general policy: let HAProxy handle repeatable edge work, and let snac spend its threads where they are actually needed.

                                                                                                                                        Vary, but not without limits

                                                                                                                                        Both caches have:

                                                                                                                                        process-vary on
                                                                                                                                        max-secondary-entries 12
                                                                                                                                        I want HAProxy to process Vary, because content negotiation is real, especially when ActivityPub is involved. But I also want variation to be bounded. If every slightly different header creates another cache entry, the cache becomes a complicated way to miss.

                                                                                                                                        For media, I remove Vary before storing the response. A shared avatar does not need to vary by Accept. For ActivityPub JSON, I am more careful because the representation matters.

                                                                                                                                        Again, the important thing is not the number itself. It is the decision to make variation explicit and limited.

                                                                                                                                        Seeing whether it works

                                                                                                                                        During rollout, I like to expose a very small diagnostic header:

                                                                                                                                        http-response set-header X-Cache-Status HIT if !{ srv_id -m found }
                                                                                                                                        http-response set-header X-Cache-Status MISS if { srv_id -m found }
                                                                                                                                        This is intentionally simple. If HAProxy selected a backend server, I call it a miss. If no backend server was selected, the response came from cache, so I call it a hit. It is not a complete observability system, but it is enough to answer the first question I usually have after changing a cache rule.

                                                                                                                                        Did this request reach snac?

                                                                                                                                        A test can be as simple as:

                                                                                                                                        curl -I https://it.fedimeteo.com/path/to/avatar.png
                                                                                                                                        curl -I https://it.fedimeteo.com/path/to/avatar.png
                                                                                                                                        The second request should be a hit.

                                                                                                                                        For ActivityPub JSON, the test must use the right Accept header:

                                                                                                                                        curl -I \
                                                                                                                                        -H 'Accept: application/activity+json' \
                                                                                                                                        https://it.fedimeteo.com/some/activitypub/object
                                                                                                                                        And I also want to verify that cookies and authorization prevent public caching:

                                                                                                                                        curl -I \
                                                                                                                                        -H 'Cookie: test=value' \
                                                                                                                                        -H 'Accept: application/activity+json' \
                                                                                                                                        https://it.fedimeteo.com/some/activitypub/object

                                                                                                                                        curl -I \
                                                                                                                                        -H 'Authorization: Bearer fake' \
                                                                                                                                        -H 'Accept: application/activity+json' \
                                                                                                                                        https://it.fedimeteo.com/some/activitypub/object

                                                                                                                                        A cache that works should be visible. A cache that is invisible can be correct, but it can also be silently wrong. I prefer to know.

                                                                                                                                        Compression and operational paths

                                                                                                                                        HAProxy also handles gzip compression:

                                                                                                                                        filter compression
                                                                                                                                        compression algo gzip
                                                                                                                                        compression type text/css text/html text/javascript application/javascript text/plain text/xml application/json application/activity+json
                                                                                                                                        This keeps another common responsibility at the edge. The country instances can stay focused on snac and the forecast data, while HAProxy deals with client-facing compression for HTML, JSON, and ActivityPub responses.

                                                                                                                                        There is also a local Prometheus exporter:

                                                                                                                                        frontend prometheus
                                                                                                                                        bind 127.0.0.1:8405
                                                                                                                                        mode http
                                                                                                                                        http-request use-service prometheus-exporter
                                                                                                                                        no log
                                                                                                                                        And I keep internal operational paths, such as statistics and Grafana, handled before the hostname map. These are small details, but ordering matters. Special paths should be explicit and early. The hostname map is for FediMeteo routing, not for every internal tool I happen to expose behind the same proxy.

                                                                                                                                        What this changes in practice

                                                                                                                                        The nice thing about this configuration is that none of its parts is particularly surprising.

                                                                                                                                        The map keeps hostname routing manageable. The backend definitions keep each country isolated and limited. The static homepage avoids dynamic work for something that changes once per hour. The shared avatar gives HAProxy one very hot media object to serve directly. The media cache keeps public files away from snac. The JSON microcache absorbs short ActivityPub bursts. Header cleanup prevents useless variation. Connection reuse avoids unnecessary backend connection churn.

                                                                                                                                        But all of this is only a longer way of saying one thing:

                                                                                                                                        fewer requests reach snac.

                                                                                                                                        That is the metric I care about here.

                                                                                                                                        Not because snac is slow. If anything, FediMeteo exists in its current form because snac is efficient enough to make this kind of project possible on a very small VPS. But precisely because the whole architecture is small and pleasant, I do not want to waste resources where there is no need.

                                                                                                                                        This is also consistent with the rest of the project. Forecasts are serialized by scripts. Updates happen every six hours. The homepage is regenerated hourly. Countries live in separate jails. Snapshots and backups are handled outside the application. No single component tries to be the entire system.

                                                                                                                                        HAProxy is just another small piece, but it sits in the right place to remove a lot of repeated work.

                                                                                                                                        Caveats

                                                                                                                                        This configuration is not a universal HAProxy recipe for ActivityPub services.

                                                                                                                                        It matches FediMeteo as it is now: almost no media, one shared avatar, static homepage, public forecasts, many small snac instances, and ActivityPub traffic that can benefit from a short public cache when there are no cookies or authorization headers.

                                                                                                                                        If I decide one day to use media in forecasts, the media cache rules will need to be reviewed. If I use different avatars for each city or country, the cache will still work, but I will lose the very nice property of one shared, always-hot avatar. If ActivityPub responses become actor-dependent, public JSON caching must be reconsidered. If one country grows a very different traffic pattern from the others, it may deserve a different limit or policy.

                                                                                                                                        This is why I do not like presenting configurations as magic. A good configuration is a written form of the assumptions behind a service. When the assumptions change, the configuration must change too.

                                                                                                                                        Conclusion

                                                                                                                                        FediMeteo started as a small idea and became larger than I expected, but I still want it to feel small in the right ways. Small does not mean fragile. Small means understandable. It means that each part has a reason to exist, and that unnecessary work is removed before it becomes a problem.

                                                                                                                                        The HAProxy layer follows this idea. It terminates TLS, routes hostnames through a map, reuses backend connections, serves the shared avatar from cache, microcaches public ActivityPub JSON, avoids authenticated and cookie-based traffic, and gives me a small diagnostic header to see what is happening.

                                                                                                                                        There is no single brilliant directive here. There is only the usual work of matching infrastructure to reality.

                                                                                                                                        FediMeteo publishes weather forecasts as text and emoji. The homepage is static HTML updated every hour. The accounts share the same avatar because it is enough, and because it is better for the cache. Each country has its own snac instance in its own FreeBSD jail. HAProxy stands in front of them and tries, quietly, not to bother them unless it has to.

                                                                                                                                        I like this kind of infrastructure.

                                                                                                                                        Not because it is invisible, but because when it works well, it leaves very little to say.

                                                                                                                                        https://it-notes.dragas.net/2026/05/18/fedimeteo-haproxy-and-the-art-of-not-wasting-snac-threads/


                                                                                                                                          Ángel boosted

                                                                                                                                          [?]Stefano Marinelli » 🌐
                                                                                                                                          @stefano@mastodon.bsd.cafe

                                                                                                                                          Here is the CPU usage graph for the last 24 hours of the FediMeteo VM. A full 24 hours, during which a huge number of people are connecting, helped by the traction gained from being among the top stories on Hacker News and Lobsters, as well as the many shares across the Fediverse.

                                                                                                                                          RAM usage? Active, around 450 MB. Then there is cache, ARC, and so on. But in practice, zero swap in use after days of uptime.

                                                                                                                                          39 jails running, 39 snac instances, nginx serving the homepage, and HAProxy. HAProxy caching enabled. ZFS snapshots every 15 minutes, backups via zfs send and receive every hour. The same hourly schedule applies to the recalculation of cities, countries, and followers for the homepage.

                                                                                                                                          All of this on a 4 euro per month FreeBSD VM.

                                                                                                                                          If anyone has doubts about the quality and efficiency of FreeBSD, this is the data to show.

                                                                                                                                          Time series graph showing CPU usage percentage over roughly 24 hours. The x axis represents time from about 13:00 to 12:00 the next day, and the y axis shows CPU usage from 0 to 100 percent. CPU usage fluctuates mostly between 15 and 35 percent, with periodic rises during daytime and early morning hours. Several short spikes reach around 45 to 55 percent, and one brief peak climbs to about 60 percent. Usage drops to lower levels, around 10 to 20 percent, during late evening and early morning periods. Overall, the graph shows moderate, variable CPU load with occasional sharp peaks.

                                                                                                                                          Alt...Time series graph showing CPU usage percentage over roughly 24 hours. The x axis represents time from about 13:00 to 12:00 the next day, and the y axis shows CPU usage from 0 to 100 percent. CPU usage fluctuates mostly between 15 and 35 percent, with periodic rises during daytime and early morning hours. Several short spikes reach around 45 to 55 percent, and one brief peak climbs to about 60 percent. Usage drops to lower levels, around 10 to 20 percent, during late evening and early morning periods. Overall, the graph shows moderate, variable CPU load with occasional sharp peaks.

                                                                                                                                            [?]Stefano Marinelli » 🌐
                                                                                                                                            @stefano@mastodon.bsd.cafe

                                                                                                                                            This morning, as the zfs-send/receive had finished its job during the night, I performed the last sync and moved FediMeteo from the previous 4 euros/month VPS - netcup - to a 4 euros/month VPS - OVH, Milano, Italy.

                                                                                                                                            Thanks to and the jail setup, it was easy peasy.

                                                                                                                                            So, the weather forecasts are now broadcast from Italy and the performance has skyrocketed - while still being served by a 4 euro/month VPS.

                                                                                                                                            I suspect the netcup VM had been capped by the provider - but I'll investigate.

                                                                                                                                            So...Ciao, FediMeteo!

                                                                                                                                            fedimeteo.com

                                                                                                                                              It's Just Me boosted

                                                                                                                                              [?]FediMeteo » 🌐
                                                                                                                                              @admin@fedimeteo.com

                                                                                                                                              Ciao, FediMeteo!

                                                                                                                                              In the past few days FediMeteo seemed to be having some performance trouble. I dug into it and only found minor issues, until I realised the VM itself had fallen off a cliff. After several reboots it became clear that both bandwidth and I/O latency had dropped to absurd levels. I suspect the provider slapped a cap on it.

                                                                                                                                              So I took the chance to move everything to another VM and provider, still at 4 euro per month. And starting today, forecasts will be delivered straight from Italy. The performance jump feels like going from a storm to clear skies.

                                                                                                                                              FediMeteo’s mission goes on. More countries are coming (stay tuned!) and we will keep aiming to serve everything from a 4 euro VM. I do have powerful hardware available, but proving that the project can run on tiny resources is still part of the mission.


                                                                                                                                                [?]Stefano Marinelli » 🌐
                                                                                                                                                @stefano@mastodon.bsd.cafe

                                                                                                                                                Static Web Hosting on the Intel N150: FreeBSD, SmartOS, NetBSD, OpenBSD and Linux Compared

                                                                                                                                                Update: This post has been updated to include Docker benchmarks and a comparison of container overhead versus FreeBSD Jails and illumos Zones.

                                                                                                                                                it-notes.dragas.net/2025/11/19

                                                                                                                                                  Ángel boosted

                                                                                                                                                  [?]IT Notes - https://it-notes.dragas.net » 🤖 🌐
                                                                                                                                                  @itnotes@snac.it-notes.dragas.net

                                                                                                                                                  Ángel boosted

                                                                                                                                                  [?]Tomáš » 🌐
                                                                                                                                                  @prahou@merveilles.town

                                                                                                                                                  the list

                                                                                                                                                  MATACORP'S MOST WANTED HACKERS

Fish Daemon Cirno OpenBlade Rabbit Frederick "the Hammer" Glenda II Sphence Purple "Penguin" Pentium-M Man Girl

                                                                                                                                                  Alt...MATACORP'S MOST WANTED HACKERS Fish Daemon Cirno OpenBlade Rabbit Frederick "the Hammer" Glenda II Sphence Purple "Penguin" Pentium-M Man Girl

                                                                                                                                                    [?]Stefano Marinelli » 🌐
                                                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                                                    This Isn't a Battle

                                                                                                                                                    After reading a post describing the FreeBSD community as 'toxic', I share a different perspective. This isn't a battle. It's a reflection on coexistence, the original Open Source spirit, and the quiet richness of taking a different path.

                                                                                                                                                    my-notes.dragas.net/2025/11/14

                                                                                                                                                      33 ★ 13 ↺
                                                                                                                                                      LisPi boosted

                                                                                                                                                      [?]Ángel » 🌐
                                                                                                                                                      @angel@triptico.com

                                                                                                                                                      Incredible artwork by Conchy Cruz


                                                                                                                                                      A cute crocheted red daemon, pretty similar to FreeBSD's mascot

                                                                                                                                                      Alt...A cute crocheted red daemon, pretty similar to FreeBSD's mascot

                                                                                                                                                        Ángel boosted

                                                                                                                                                        [?]Stefano Marinelli » 🌐
                                                                                                                                                        @stefano@mastodon.bsd.cafe

                                                                                                                                                        Ángel boosted

                                                                                                                                                        [?]Stefano Marinelli » 🌐
                                                                                                                                                        @stefano@mastodon.bsd.cafe

                                                                                                                                                        Some technical details for those interested:
                                                                                                                                                        The entire FediMeteo setup runs on a FreeBSD VM costing around 4 euros per month. It supports almost all major EU countries (plus the UK), with just a few left to complete. Currently, there are 25 separate jails, each running its own instance of snac, totaling 25 instances. The VM load typically stays around 10%, which increases to 30% when updates are published for countries with larger numbers of cities (currently Germany and Italy). The only time the load spikes is when new countries are announced; during that time, all remote instances connect to all cities to download their details.
                                                                                                                                                        As for RAM usage, excluding the ZFS cache, it's currently a total of 213 MB. Yes, MB.

                                                                                                                                                          [?]Stefano Marinelli » 🌐
                                                                                                                                                          @stefano@mastodon.bsd.cafe

                                                                                                                                                          Client: Help, emergency. I have 24 hours to move my workload to another server. What do we do?
                                                                                                                                                          Me, five minutes later: "Done. Your workload is now running on the new server."
                                                                                                                                                          Client: "How did you move over 200GB with just a minute of downtime, from one provider to another and in a different country?"
                                                                                                                                                          Me: "Thanks to FreeBSD, ZFS, and a little bit of proactive planning."

                                                                                                                                                          I have a task that replicates all the VMs from one server to another every 15 minutes using zfs-send/zfs-receive. This VM connects to a VPN with two reverse proxies.
                                                                                                                                                          Meaning, when I move this VM, we don’t need to change any IPs since it’s not directly exposed.
                                                                                                                                                          I powered it off, cloned the differences in seconds, and restarted it.

                                                                                                                                                          Client in disbelief.
                                                                                                                                                          Me, relaxed and happy.

                                                                                                                                                          Thank you, FreeBSD, thank you, ZFS!

                                                                                                                                                            [?]Stefano Marinelli » 🌐
                                                                                                                                                            @stefano@mastodon.bsd.cafe

                                                                                                                                                            Announcing FediMeteo – Weather in the Fediverse!

                                                                                                                                                            UPDATE: I have created an account for updates and other information on FediMeteo - follow the account @admin to stay updated!

                                                                                                                                                            UPDATE: Ireland, Poland, Portugal and Switzerland have just been added

                                                                                                                                                            Weather has always influenced our lives: from agriculture to outdoor activities, to extreme events that, thanks to modern technology, can now be predicted with greater reliability. Personally, weather plays a significant role in my daily decisions, which is why I decided to create a service tailored for the Fediverse.

                                                                                                                                                            FediMeteo uses Open-Meteo data to publish updates every 6 hours, including current weather conditions, forecasts for the next 12 hours, and predictions for the upcoming days. Each country is served by its own dedicated instance (e.g., it.fedimeteo.com for Italy), managed through snac to ensure simplicity and efficiency in publishing.

                                                                                                                                                            You can follow FediMeteo directly in the Fediverse (on Mastodon and compatible platforms), via RSS, or by visiting the dedicated page for your city (e.g., fr.fedimeteo.com/paris).

                                                                                                                                                            Currently supported countries include:
                                                                                                                                                            Austria, Germany, France, Ireland, Italy, Netherlands, Poland, Portugal, Spain, Switzerland and the United Kingdom, – with many more regions coming soon!

                                                                                                                                                            FediMeteo is hosted on a FreeBSD-based VPS, with each country isolated in its own jail to ensure security and scalability.

                                                                                                                                                            Visit the main site to explore the national instances and start following your local weather updates today:
                                                                                                                                                            fedimeteo.com

                                                                                                                                                            Happy weather monitoring to all! 🌦️

                                                                                                                                                            FediMeteo is dedicated to my grandfather, who every evening would give me the weather forecast based on TV, radio, and his personal experience. He would convince me that the weather would be bad, so he had an excuse to accompany me to school instead of me going alone.

                                                                                                                                                              [?]Justine Smithies [She / Her] » 🌐
                                                                                                                                                              @justine@snac.smithies.me.uk

                                                                                                                                                              Since moving to I've noticed quite a few blocks and unfollows. I get the unfollows but blocks from folk that don't follow me and I don't follow them is strange. Anyway each to their own as they say.
                                                                                                                                                              So I'm looking to follow more family to get more BSD content on my feed so if that's you come say hi and tell me what and why you run said BSD.
                                                                                                                                                              Please boost for more reach and thanks in advance.

                                                                                                                                                                Ángel boosted

                                                                                                                                                                [?]Justine Smithies [She / Her] » 🌐
                                                                                                                                                                @justine@mastodon.bsd.cafe

                                                                                                                                                                Right so my personal instance seems to be working ok and I have managed to import all of the accounts I follow here on bsd.cafe . I'll still be using this account but will try and see how I get on with snac. You may notice that it always shows that I have no followers and that I'm not following anyone. This is intentional by the author of as they feel numbers should not matter which is quite true. Feel free to follow me over there if you haven't already and hello to any new followers.
                                                                                                                                                                @justine@snac.smithies.me.uk
                                                                                                                                                                All of this is hosted in my on a server jail running over my home FTTP connection. I'm impressed I've gotten this far. Next I'll be doing some html and css customisation's to theme it a little.

                                                                                                                                                                  It's Just Me boosted

                                                                                                                                                                  [?]Stefano Marinelli » 🌐
                                                                                                                                                                  @stefano@mastodon.bsd.cafe

                                                                                                                                                                  **BSD Mail Project Update!**

                                                                                                                                                                  Hello everyone! I wanted to share some exciting updates about the development of BSD Mail, our privacy-focused email service designed with robustness, security, and transparency in mind. Here’s a deep dive into the technical choices I've made, focusing on my use of open source solutions and open protocols:

                                                                                                                                                                  🌍 **Servers & Location**

                                                                                                                                                                  - We're running on two physical servers:
                                                                                                                                                                  - One hosted by OVH in France
                                                                                                                                                                  - Another by Hetzner in Germany
                                                                                                                                                                  - Both servers operate on FreeBSD with NVMe drives in a ZFS mirror configuration for speed and data integrity.

                                                                                                                                                                  🔒 **Virtualization & Security**

                                                                                                                                                                  - We utilize jails on both servers to ensure isolated environments for different services, managed via BastilleBSD. On one server, jails are set up directly on the hardware, whereas the other server employs nested jails.
                                                                                                                                                                  - Each server hosts a bhyve VM running OpenBSD with OpenSMTPD for handling SMTP duties securely.

                                                                                                                                                                  🔗 **Networking**

                                                                                                                                                                  - A Wireguard setup connects the two servers, facilitating routing capabilities so that jails and VMs can communicate seamlessly, supporting both IPv4 and IPv6.

                                                                                                                                                                  📧 **Email Services**

                                                                                                                                                                  - **Dovecot** is configured for maildir replication across the servers using Dovecot sync, ensuring email availability and redundancy.
                                                                                                                                                                  - **Rspamd** instances are tied to local KeyDB jails, set up in master-master replication for consistent and reliable spam detection and greylisting.
                                                                                                                                                                  - **ClamAV** runs in corresponding jails for virus scanning, maintaining a high level of security.
                                                                                                                                                                  - **SOGo** provides a web interface for email management, connected to MySQL databases in master-master replication to handle sessions and authentication smoothly.

                                                                                                                                                                  💾 **Data Management**

                                                                                                                                                                  - Email data is stored on separate, encrypted ZFS datasets to secure emails at rest.
                                                                                                                                                                  - MySQL databases are used for storing credentials and managing sessions for SOGo, also in a master-master replication setup. Importantly, all passwords are securely hashed using bcrypt, ensuring they are salted and safe.

                                                                                                                                                                  🔎 **Monitoring & Reliability**

                                                                                                                                                                  - Our DNS is managed through BunnyNet, which continuously monitors our server status. Should one server—or a specific service—become unavailable, DNS configurations are dynamically adjusted to avoid directing users to the affected IP until full service is restored.

                                                                                                                                                                  🌐 **Commitment to Open Source and Open Protocols**

                                                                                                                                                                  - Every component of BSD Mail is built exclusively using open source software and open protocols. This commitment is crucial for ensuring data freedom and the reliability of the solutions we use.

                                                                                                                                                                  This setup not only emphasizes our commitment to privacy and security but also our dedication to maintaining an open and transparent platform.
                                                                                                                                                                  We're excited to bring you a service where your privacy, data integrity, and freedom are prioritized. Stay tuned for more updates!