sh.itjust.works Main Community

8504 readers
1 users here now

Home of the sh.itjust.works instance.

Matrix

founded 3 years ago
MODERATORS
1
 
 

To the members of SJW, our friends across the Fediverse, and the curious passersby, this update is for you.

Now that we are well into 2026, I wanted to look back at how 2025 unfolded and share some insight into SJW’s finances, infrastructure, traffic trends, and priorities for the year ahead.

2025 Finances

One of the biggest changes in 2025 was the introduction of member-supported funding.

In January of 2025, I opened donations to help cover the cost of operating SJW. The goal was to begin moving away from a model funded entirely by me and toward a community-supported model that can remain financially sustainable over the long term.

Throughout 2025, we received $3,239.41 in net donations and spent $1,396.14 on operational expenses.

During the year, we also experienced a few hardware failures, most notably a failed power supply and hard drive. Thanks to the redundancy built into our servers, neither failure resulted in a service disruption.

I was able to repurpose a compatible power supply from a decommissioned server at no cost. I also personally covered the replacement hard drive before prices went through the roof. While donation funds could have covered these expenses, I wanted to preserve as much of the balance as possible for a larger hardware upgrade.

All amounts below are in Canadian dollars.

Category Amount Additional information
Net donations received $3,239.41 January through December 2025
S3-compatible storage $69.62 Paid through July 2026
Email service $70.60 Paid through July 2026
Colocation $1,200.00 2025 infrastructure hosting
Domain name $55.92 Domain registration
Total expenses $1,396.14
Remaining balance $1,843.27 Reserved for operations and future infrastructure

This year, I hope we can raise enough to help purchase newer hardware. Unfortunately, as many of you are probably aware, the rapid growth of AI infrastructure has significantly increased the price and demand for many server components.

Traffic Trends

This is where things become particularly interesting and, at first glance, a little puzzling.

Based on our traffic logs and Cloudflare data, overall traffic approximately doubled during 2025, despite SJW adding only around 4,000 active accounts during the same period.

As of January 2026, when I first began preparing this update, Cloudflare was reporting:

  • More than 300 million pages served per month
  • Approximately 6 million unique visitors over a 30-day period

These are enormous numbers, but they almost certainly do not represent six million individual people.

I suspect that at least 50 to 60 percent of this activity, and possibly more, comes from bots, scrapers, automated crawlers, vulnerability scanners, archival services, and other automated systems. Some of this activity may also come from services gathering public information for traditional search engines and newer AI-powered search tools.

I recently implemented Anubis to help reduce abusive automated traffic. While it cannot prevent every bot or scraper from accessing the site, it makes large-scale automated collection more difficult and has helped us begin addressing the problem.

Hardware and Infrastructure

Given these traffic trends and some of the performance issues we have encountered, our current hardware is reaching the point where I need to seriously consider replacing or upgrading it.

I recently changed our Lemmy deployment to use horizontal scaling. In simpler terms, we now run multiple Lemmy service instances in parallel and distribute incoming traffic between them. This has helped improve the instance’s ability to handle periods of heavier activity.

However, software improvements can only take us so far. Newer hardware would give us more capacity, better performance, and additional room to build resilience into the platform.

I would also like to explore bringing our primary S3-compatible object storage in-house while maintaining an appropriate off-site backup strategy. This would reduce our reliance on third-party storage providers while giving us more control over privacy, performance, and redundancy.

2026 Priorities

Our main infrastructure priorities for 2026 are:

  • Upgrade or replace aging server hardware
  • Add further redundancy to critical services
  • Continue improving horizontal scaling
  • Reduce the impact of abusive automated traffic
  • Explore self-hosted object storage
  • Deepen our collaboration with Fedecan

Fedecan

As some of you may remember, we previously shared our intention to join Fedecan, an organization with which we share common values and a similar vision for the Canadian Fediverse.

That transition has now been finalized. SJW is associated with a registered Canadian nonprofit organization and can benefit from its banking, administrative, and nonprofit structure.

The initial banking and legal integration is complete, but our collaboration will continue to deepen as we work toward a larger shared vision and develop common guidelines.

Donations are now processed through Fedecan, but funds donated specifically to SJW are tracked separately and remain reserved for SJW’s operating costs, infrastructure improvements, and future service expansion.

Donations

As outlined above, one of our main goals this year is to upgrade our existing hardware and improve the resilience of the services supporting SJW.

I am still evaluating the available hardware options and will share more specific information once the upgrade plan and expected costs have been finalized.

If you have the means and would like to support SJW, donations of any size are greatly appreciated. Every contribution helps us maintain the instance, prepare for future growth, and reduce how much of the operating cost must be covered personally.

Regardless of how much we raise, I'm committed to keeping SJW running. I will continue looking for suitable replacement hardware and am prepared to personally contribute toward any shortfall required to support the next generation of our infrastructure.

If you'd like you can contribute through either of the following platforms:

Thank You

In closing, I want to thank our admins and mods, who continue to volunteer their time to help make SJW a safe and welcoming place.

I also want to thank our members who have chosen to make the Fediverse, and SJW in particular, their home. Whether you donate, contribute to discussions, report problems, help other members, or simply spend time here, you are part of what keeps this community alive.

Thank you for being you.

And if nobody has reminded you lately: you are great, you are loved, and most importantly, you are enough.

TheDude ✌️

2
 
 

cross-posted from: https://lemmy.ca/post/67952523

This is the first big step in the process to develop comprehensive guidelines for the Fedecan non-profit and the various platforms.

While this will mostly involve converting tacit knowledge and experience into an explicit written form, we expect that this process will inevitably bring up some points of disagreement on the best way to deal with different issues. We ask everyone participating in these discussions to please contribute constructively and in good faith. We encourage you to bring up any concerns or issues you have with the proposed structure and drafted guidelines, so that we can work together to fix them early on. However, in order to keep a productive environment for those discussions, we will be pruning any comment chains that devolve into personal attacks, slap fights, etc.

To help ground your feedback, consider these thought experiments when evaluating a potential guideline:

  • Veil of ignorance: Would it still feel fair to you if you switched places with someone else on the platform (ex. a new user, a moderator, an admin, a member of a vulnerable group, etc.)?
  • Equal Applicability: These rules will be enforced uniformly on everyone. A poorly written rule that helps "your side" today, can easily harm "your side" in the future as circumstances change.

The full guidelines, including governance details like the annual review cycle, can be found on the website: https://fedecan.ca/en/guidelines/

We plan to structure the guidelines as follows:

diagram of the tiers that are described below

Tier 1: Fedecan Rules

Internal Conduct

These rules apply to Fedecan team members (directors, officers, admins, and anyone with elevated access). They set expectations for how team members should act.

Universal Rules

These are the baseline rules that apply to every user on every Fedecan platform. They cover the things that are prohibited by Canadian law (threats, hate speech, CSAM, non-consensual intimate imagery) as well as universal policy rules (privacy/doxxing, harassment, fraud, content that could cause harm, labelling of sensitive content, etc.).

Tier 2: Platform-Specific

Each platform has different functionality and norms, so this is where we can be more specific with the rules. The threadiverse platforms (lemmy.ca, piefed.ca, sh.itjust.works) share similar rules around community creation, moderation, vote manipulation, and content labelling. Pixelfed has its own rules tailored to its platform.

Tier 3: Community-Level Rule Templates

These are optional templates that communities can link to, or use as a starting point for their own rules. The idea is that moderators can point users to a clearly written explanation of why a rule exists, and any relevant exceptions, rather than trying to fit everything into the sidebar. Additionally, if many communities are enforcing a particular rule in the same way, then users will have an easier time understanding and following them.

The post title standards template has been drafted, and we plan to add more as the need arises. I have a few others that are in the works, but they have some overlap with the other sections, so I thought that it would be better to let people discuss first.

3
 
 

The current domain is basically invisible to search engines. sh.itjust.works is too long, the .works TLD isn't SEO-friendly, and the "sh." subdomain doesn't add value. Why not use something shorter like itjustworks.com or itjustworks.org instead?

Is this deliberate? Would appreciate if an admin could explain the reason.

4
 
 

It seems the new message notification bubble (number next to the bell) stays up until I Mark All As Read and then go back to the comments page. If I Mark All As Read and continue browsing, it stays up.

Firefox Desktop / Linux.

5
 
 

Because I'd guess it is--a covered teacup with a misplaced handle, random "generic devices" scattered about, cables that go nowhere....

Any interest is an open call for a replacement image for the server?

6
 
 

Where can I go to learn about homeless shelters in ontario please?

Amd Im talking about homeless shelters located in ANY, YYES A.N.Y. part of ontario. It doesnnt matter if its cornwall, fort severn, windsor, niagara falls, thunder bay, lonndon, whatever.

Are they all full as Ive heard? Can I confirm this for myself? Is that why they always drop the call when you call 211?

How long does one get to stay there and how much does it cost to stay there per month?

Thank you.

7
 
 

Hi folks, anyone else noticed that https://oldsh.itjust.works/ doesn't work anymore or is it just me? Doesn't work for me at work or at home and they're on different setups...

8
 
 

Hi there! 👋

We’re a friendly global team residing in the United States and the United Kingdom, focused on one simple goal: helping people like you generate reliable, extra income from home.

Right now, we’re looking for residents of North America and Europe who are interested in a straightforward, flexible side role. Whether you're between jobs, finding that government support doesn’t go far enough, or just want a little more breathing room in your monthly budget—we’ve got an opportunity that might fit perfectly into your life.

We believe in making work accessible, supportive, and genuinely worth your time. If this sounds like the kind of opportunity you’ve been looking for, we’d love to hear from you.

👉 Reach out today—let’s chat about getting you started!

9
 
 

Voyager suddenly stopped working with SJW today. The last time this happened, it was because SJW needed an update of some sort. Is that the case this time too?

@TheDude@sh.itjust.works

10
 
 

cross-posted from: https://sh.itjust.works/post/63880645

Issue: Tesseract has a hardcoded hidden instance blacklist, and an even more obfuscated censorship list of various users, instances, communities, and general regex matches.

Also /c/modabuse. Also /c/yepowertrippinbastards. Also lemmy.ml/c/worldnews, comrade, ACAB, and 552 individual accounts across 67 instances, about half of them on lemmy.world.

None of this is in the source code. It's downloaded at runtime from a file nobody has ever looked at.

If you're just tuning in

Tesseract is a third-party web frontend for Lemmy, maintained by asimons04 and licensed AGPL-3.0. Admins deploy it on their own servers alongside or instead of lemmy-ui, and there are public instances of it people use to browse Lemmy generally. If you've used a Lemmy site that didn't look like stock Lemmy, there's a fair chance it was this.

Last week db0 posted a PSA: Tesseract contains a blacklist of instance domains compiled directly into the application. 32 of them. Admins can't see it, can't configure it, and aren't told it's there. Connect to a listed instance and the app tells you it's "incompatible," which is not true.

I went through the code to see how that was implemented. The hardcoded list turns out to be the small half of the system.

There's a second filter policy fetched over HTTP every time the app loads. It isn't in the git repository. It's unauthenticated and world-readable, so anyone can pull it. Right now it carries 552 user accounts, 2,275 username patterns, 54 instances, 97 communities, 289 keyword patterns and 351 domains, with every category set to hide matches rather than flag them. Not collapsed behind a click. Simply absent, with no indication anything was removed.

Verify all of it in ten seconds

curl -s https://tesseract.dubvee.org/tesseract/api/system/policy \
  | base64 -d | gunzip > policy.json

That's the live policy, base64-wrapped gzip, 111KB of JSON when it unpacks. There's a stale fallback copy at /data/policy.dat as well.

It filters criticism of moderators

  • lemmy.sdf.org/c/modabuse — listed
  • lemmy.dbzer0.com/c/yepowertrippinbastards — listed
  • lemmy.dbzer0.com/c/YPTBcirclejerk — listed
  • community regex power ?tripping?
  • keyword censoring me

Call the rest of it whatever you like. This part is not spam defence.

It filters words

The 32 community name patterns include Communis(t|m), Conservativ(e|es|ism), Leftis(t|m), Libertarian(ism)?, ^Green Part(y|ies), Zionis(t|m), (Police|Cops), guillotine and billionaire.

Keywords include comrade, ACAB, neoliberal, proletaria(n|t) and death to.

Filtered communities on instances that aren't blocked: lemmy.ml/c/worldnews, lemmy.today/c/news, lemmy.ca/c/politicalnewscanada, lemmy.ca/c/usa, infosec.pub/c/strategic_unions.

The 552 users aren't bots

67 instances. 272 on lemmy.world alone, 40 on sh.itjust.works, 19 on lemmy.ca, and 28 instances contributing exactly one person each.

355 of the 552 usernames are plain alphabetic, twelve characters or under, median length eight. Only 36 look like spam registrations. A bot list looks like the opposite of that.

Seven of them aren't even Lemmy. There are Mastodon and Friendica accounts in there: people who have never used Lemmy, hidden by a Lemmy frontend, with no possible way of finding out.

I have the list and I'm not posting it. Most of these are ordinary people who got pattern-matched, and 552 names on this comm is a harassment target inside an hour. Run the command above and grep for yourself.

And it lies about it

When the instance block fires you get: "Incompatible Instance. Not Supported. $instance is not compatible with Tesseract."

Nothing is incompatible. It's a policy decision dressed as an API error, and it's what had db0 chasing a version mismatch that never existed.

For the hidden users, communities and keywords, you get no message at all.

Admins can't switch it off

Tesseract has env vars for PUBLIC_DOMAIN_BLACKLIST, PUBLIC_FAKE_NEWS_BLACKLIST and the shortener lists. There is none for either blocklist. enableToxicMode bypasses the other filters and explicitly not this one.

Self-host it and you cannot disable this, nothing in your config admits it exists, and the contents can change without you pulling a commit.

Before someone says it

A lot of that domain list is real spam defence. It filters conservatism as well as communism. "It targets the left" doesn't survive the data and I'm not going to pretend it does.

The problem is that spam filtering and political editorial got welded into one undocumented, remotely-updatable blob, shipped hidden, to admins who've never read it and users who don't know it's there. The spam work is what makes the rest unauditable: "it's a spam list" answers every individual question and none of the whole.

And /c/modabuse is not spam.

Asks

  1. Publish the runtime policy in the repo, or kill the endpoint.
  2. Stop reporting a policy block as a technical incompatibility.
  3. Tell users when something's been hidden. One line.
  4. Give operators an off switch, like every other blacklist in the codebase has.

It's AGPL-3.0 and db0 already forked it. That's the licence working as designed. But forking isn't disclosure, and the admins who need this are precisely the ones with no reason to go looking.

If you run Tesseract, you are relaying a 111KB moderation policy you have never read, under your instance's name, to users who don't know it exists.

I disagree with some of the assertions put forth above about it not targeting the left, etc. And I don't think the asks is relevant, because we should no longer be trusting anything from this person.

Policy file here, for archival purposes: https://file.garden/amIRhTctI0qld2r5/policy.json

11
 
 

If so, what are the coords? I can't find it on the mega-template.

12
 
 

I just posted my first band interview with a bunch of pics.
https://sh.itjust.works/post/63544454

I'm pretty sure my graphics, while definitely not hi-rez, are too big. I'm choking the system when I upload them, and they don't render during page view very well either.

I'm just taking pics with my crappy cell phone.
I upload them by opening the pic in MS Paint, select all, copy, and then paste it directly into the post.

Just given the results I've had so far, and my intent to post a LOT more pics, perhaps I should tune this process up.

How would you do it?

13
1
submitted 1 month ago* (last edited 1 month ago) by AwesomeLowlander@sh.itjust.works to c/main@sh.itjust.works
 
 

My app (Thunder) has been having issues connecting for the past few hours, while the website has been up and running. Just wondering if anybody else is having issues.

Also not having any trouble connecting to other instances, just this one.

Edit: Seems to be back

14
1
submitted 1 month ago* (last edited 1 month ago) by dbtng@sh.itjust.works to c/main@sh.itjust.works
 
 

What's the detail with YouTube videos on this instance?
If I'm on this instance, videos in a post don't render. Instead I see a big black window with this error text.

Watch video on YouTube
Error 153
Video player configuration error

You can just right click the link and go to youtube to see it, its not a complete disaster.
I do sort of need to figure this out tho. I'm doing my best to mod a music comm, so the videos are pretty important.

I've tried testing from other instances ... and there's no problem. I have accounts on eviltoast.org (regular lemmy) and moist.catsweat.com (mbin). No problem viewing those same posts from either of those instances. I didn't even notice the issue until I started using my sh.itjust.works account regularly.

It doesn't seem to matter who made the post or how old it is. When I'm logged into my sh.itjust.works account, all of the youtube posts show the black window.

I normally use firefox+adblockers, but I have sh.itjust.works whitelisted in ublock. I've also tested in my completely clean Vivaldi.

I've tested from various machines. I consistently see the empty black window only when I'm viewing these posts through the sh.itjust.works instance.

I'm a newbie mod, but this is not even a mod thing. I'm just reading a post here. Basic internet stuff. Got any help for me?

15
 
 

This is the first time I'm experiencing downtime for this instance, so I appreciate that a lot. Is anyone else currently experiencing troubles? Anyone know what is going on?

16
 
 

I like posting to stoner_rock@sh.itjust.works.
It has subscribers, I'm not the only one there, but it's been a bit stagnant. I think it could use a cleanup, maybe people might be more interested in it if there was more going on.
I'd like to adopt the com and do a few things with it.

The mod is niladmirari@sh.itjust.works. They last logged into lemmy 2024 and only ever posted a few things.
I messaged them, and was unsurprised to get no reply.

Do I need to have a sh.itjust.works account? I could sign up for one if that's the case. I have 2 lemmy accounts already, and didn't really want a 3rd, but if those are the rules, that's fine.

I expect this to be an uncontroversial request. I clearly use the comm, and its clearly abandoned.
Give me some feedback here, and I'll take whatever next steps are needed.

17
18
 
 

All the image files on there are down. It says they'd be shutting down on July 2nd... it's not even June and nothing submitted to them shows up on any other end. I swear, every time I think I have more time to do something, someone unprovokedly immediately reveals this to be untrue.

19
1
submitted 4 months ago* (last edited 4 months ago) by QuinnyCoded@sh.itjust.works to c/main@sh.itjust.works
 
 

since about yesterday I can't see my own posts on lemmy.world or lemmy.blahaj.zone subs when I go to my accounts on those instances. Is this happening for anyone else?

I don't see an announcement for maintenance or anything 🤷‍♀️

post for example:
https://sh.itjust.works/post/59231797 (lemmy.world)
https://sh.itjust.works/post/59232374 (lemmy.blahaj.zone)

20
1
browse all (sh.itjust.works)
submitted 5 months ago* (last edited 5 months ago) by autumnfallsforbait@sh.itjust.works to c/main@sh.itjust.works
 
 

>by default blasted with bot copies of porn subs from leddit, including pedobait ones like barelylegalteens

what did the instance admins mean by this

21
 
 

Howdy are you able to delete this comm:

https://sh.itjust.works/c/usgreenlandwar

thanks

22
 
 

not sure if this is an issue just with this instance, or a general lemmy problem.

I have the options "Open links in a new tab" checked, but nothing ever opens in a new tab. this has been a problem for me for almost 3 years on this instance. i just assumed it would be fixed in an update some day.

using firefox on debian, if that makes a difference

23
 
 

I'm new to Lemmy, days not weeks. Liking it so far and I'm trying to contribute in a positive way to the instance.

I have one usability issue, trying to figure out which replies in a post are new since I last read it. I see the number like (4 New) telling me how many, but not which.

Sorting by "New" hardly helps because of the threaded display. Threading is a good thing, IMO, since it preserves the flow of the conversation. But new replies to older replies get buried with a "New" sort. When the post has only a few replies total, I can keep up simply by re-scanning the whole thread. On more popular posts that becomes infeasible.

Please don't beat me up too bad if I'm missing an obvious thing! I saw the user settings, "Show Read Posts", but that seems to be post level, not reply level.

Editing because I am an idiot: I use the web interface through https://sh.itjust.works/.

24
 
 

Do SJW and Fedecan have an explicit commitment not to store user data in the United States? If not, is that technically feasible given the hosting available? Just to be clear, I’m not asking about data that’s obviously published (e.g. posts), but data that’s private (email addresses, IP address logs, etc). Thanks!

25
 
 

Hello - I am wondering if there are any alternative frontends for sh.itjust.works on desktop.

Sorry if there is a list available somewhere already!

view more: next ›