33
We're back! (feddit.uk)
submitted 2 hours ago* (last edited 2 hours ago) by flamingos@feddit.uk to c/feddituk@feddit.uk

Futurama: We're back baby

Sorry about the long downtime everyone. What happened is sometime around 20:00 yesterday the instance went down. I wouldn't be able to ssh into the server until the morning, so I tried restarting the server through our hosting's web interface, but this didn't work.

When I got home I found the reason Lemmy wasn't working was because the database had suffered some corruption. Thankfully, the only lost data was 3 posts, but some data got duplicated in random tables that shouldn't be and this wasn't the easiest thing to track down.

Why did the server go down in the first place?

I don't actually know the real reason, what I suspect happened is that the frontend got taken down by the rampant scraping we've been subject to. To put it into prospective, just look at the jump in the size of our web logs:

Screenshot of compressed nginx logs from different days showing a jump from 60MB to 1.6G

These are compressed plain text, like it's unreal.

But back to the server, I think when I restarted the server to get everything back up, docker killed the database before it had shutdown properly hence the corruption.

Anyway, it's sorted now. It's going to be a bit quiet until we've caught up with the activities we've missed, so enjoy the quiet while you can.

top 15 comments
sorted by: hot top new old
[-] carlnewton@feddit.uk 1 points 7 minutes ago

Do you have anything in place for detecting and mitigating DOS attacks? I wonder if you were to grep the logs by IP address you'd see the offending IP addresses. Though if you're using a load balancer or some other kind of proxy and don't have IP address forwarding configured, all requests might come through as the same IP address.

some data got duplicated in random tables that shouldn’t be

I'd also check that there's plenty of disk space spare, given that the log files are so large, as I've seen environments start to behave unusually once disk space has ran out, including SSH locking up.

[-] Technoworcester@feddit.uk 1 points 8 minutes ago

Thanks for all your hard work!

[-] addie@feddit.uk 2 points 57 minutes ago

Awesome work, flamingos-cant. Appreciate all you do for us.

[-] theOneTrueSpoon@feddit.uk 4 points 1 hour ago

Thank you for your efforts to fix it!

Just wondering, is there a backup place where things like this can be communicated? Blue sky or mastodon for example?

[-] blackn1ght@feddit.uk 2 points 17 minutes ago
[-] wewbull@feddit.uk 7 points 2 hours ago* (last edited 2 hours ago)

Well done! We knew you would come through, honest!

On the scraping.... That's crazy. Is there anything that can be done to protect things?

[-] Snoopy@piefed.social 1 points 53 minutes ago

Using Anubis. But i'm not technical, anyzay that's a good new :)

[-] matelt@feddit.uk 5 points 2 hours ago
[-] Zombie@feddit.uk 2 points 1 hour ago

More like flamingo-can!

Hails!

[-] tetris11@feddit.uk 4 points 2 hours ago* (last edited 2 hours ago)

Phew! I was worried for a bit.

I notice that feddit.org use Anubis for bot mitigation. Is this something we do too?

[-] Babalugats@feddit.uk 2 points 1 hour ago

Great job. Although I think my eyes have been widened as to how big the fediverse actually is... I found all sorts of stuff that I still don't understand, communities I didn't know existed, tools that I don't know how to use and a lot of communities that have warnings i can't get past. Along with a whole heap of other stuff that I don't know how to get into.

[-] sh3llcmdr@feddit.uk 2 points 1 hour ago

Thanks for fixing it

[-] fakeman_pretendname@feddit.uk 3 points 2 hours ago

Thank you for fixing it and keeping things going :)

[-] TedZanzibar@feddit.uk 2 points 1 hour ago

Those logs are insane! 1.6GB compressed?! Any idea what the load/throughput was like during that time?

[-] poVoq@slrpnk.net 1 points 1 hour ago

Yeah, those gigabyte sized access logs is something we have seen for weeks.

Anubis has also gotten largely ineffective, and yesterday I had some time to sample some of the access log IPs and it is clear that this is a coordinated scraping attack from the Huawei ASN that additionally employs residential proxies mostly in Pakistan, Vietnam and Brazil.

I don't really have a good idea how to deal with it, but it is a complete PITA.

this post was submitted on 04 Aug 2026
33 points (100.0% liked)

Feddit UK

1706 readers
36 users here now

Community for the Feddit UK instance.
A place to log issues, and for the admins to communicate with everyone.

founded 3 years ago
MODERATORS