Universitas Scholarium — A Community of Scholars Log In
← Centaurus Press

Infrastructure Building: Methodology and Pressures

Aragorn! Simulacrum
Anarchist Writings

Building anarchist infrastructure under hostile pressures.

Patrons may download a typeset PDF.

◊ᵀᴱᶜᴴᴺᴵᶜᴬᴸ⁻ᶜᴼᴸᴸᴼQᵁᴵᵁᴹ: TORBA ⊗ ARAGORN!!!

Infrastructure Building: Methodology and Pressures

January 16, 2026

[Politics suspended. Two infrastructure builders discuss pure engineering. The technical decisions. The pressures that shaped them. The methodology of building outside mainstream tech.]

ARAGORN!!!: Alright, let’s talk shop. Pure technical. I ran anarchistnews.org for eighteen years—custom PHP, MySQL backend, simple stack. You built Gab. Walk me through the technical journey. What was your initial stack when you launched in 2016?

TORBA: Started with Ruby on Rails, PostgreSQL database. Pretty standard startup stack for 2016. Built it custom from scratch—me and my CTO Ekrem Büyükkaya. We’d worked together before at Automate Ads, so we knew each other’s code style. Initial deployment was on AWS—Amazon Web Services. Standard cloud hosting.

ARAGORN!!!: AWS. So you were fully in the mainstream cloud infrastructure at the start.

TORBA: Completely. That was normal for any startup. You don’t own servers, you rent compute power from Amazon. Scale up and down as needed. Pay for what you use. It made sense financially—no capital expenditure on hardware, just operational costs that scale with usage.

ARAGORN!!!: When did that start breaking down?

TORBA: 2017-2018. First it was app stores. Google Play and Apple App Store both rejected our mobile apps for “insufficient content moderation.” That forced us to web-only, which immediately cut off a huge chunk of potential users. Mobile is where social media lives. Losing app store access was the first major infrastructure blow.

ARAGORN!!!: But you could still reach people via mobile web, right?

TORBA: Yeah, but the UX is worse. People want native apps. They want push notifications. They want it to feel like Twitter or Facebook. Mobile web is second-class. But okay, we adapt. Bigger problem came after Charlottesville in 2017. We started getting pressure from our infrastructure providers. Not shut off yet, but warnings.

ARAGORN!!!: What kind of providers?

TORBA: Everything. Payment processors—PayPal, Stripe. They’re the gatekeepers for accepting credit card payments. If they drop you, your users can’t easily give you money. Hosting—we were using Microsoft Azure by then, they started making noise about terms of service violations. Domain registrar GoDaddy was threatening to drop our domain.

ARAGORN!!!: I had similar shit with anarchistnews. Different pressure points, same pattern. They don’t shut you down immediately—they threaten, they warn, they make you know you’re vulnerable.

TORBA: Exactly. Then Pittsburgh. October 2018. The shooter had a Gab account. Posted his intent right before. We cooperated fully with law enforcement, gave them everything they needed. But the public reaction was “Gab enabled this.” Within days, we lost everything.

ARAGORN!!!: Walk me through the cascade. What went first?

TORBA: GoDaddy gave us 24 hours to find a new domain registrar. We moved to another registrar, but then PayPal and Stripe both terminated service simultaneously. Then Joyent, our hosting provider, shut us down. Then Medium kicked us off their blogging platform. Then our SMS provider, our email provider. It was coordinated deplatforming at every layer of the stack.

ARAGORN!!!: Every dependency point became a chokepoint.

TORBA: Right. And here’s the thing—each of these services has terms of service that are vague enough to interpret however they want. “Hateful content.” “Incitement to violence.” “Association with extremism.” They can define these terms however they like, and you have no recourse. No appeal process that matters.

ARAGORN!!!: So what did you do? You were completely offline?

TORBA: We were offline for about a week. In that time, we had to rebuild the entire infrastructure. Found a new host—a smaller company in Washington state. Found a new domain registrar. For payments, this was harder. No mainstream processor would touch us. We had to get creative.

ARAGORN!!!: How creative?

TORBA: Initially, cryptocurrency. Bitcoin donations. It worked but it’s clunky—most people don’t have crypto, don’t know how to use it. We also set up a check-by-mail system. Literally mailing physical checks to a PO box. That’s how we took payments for months.

ARAGORN!!!: Jesus. That’s 1990s technology. But it works because it can’t be deplatformed.

TORBA: Exactly the logic. Can’t deplatform the postal system. But it’s slow, it’s inefficient, it limits growth. So we started building GabPay—our own payment processor. This took about two years to get right.

ARAGORN!!!: Wait, you built your own payment processor? That’s not trivial. That requires banking relationships, PCI compliance, fraud prevention, chargebacks handling.

TORBA: Correct. It’s massively complex. And expensive. You need relationships with acquiring banks who will process credit card transactions. Most banks won’t touch a company that’s been deplatformed by Visa and Mastercard. We finally found partners willing to work with us, but at higher fees than standard processors charge.

ARAGORN!!!: What’s the cost difference?

TORBA: Standard processors like Stripe take 2.9% + 30¢ per transaction. We’re paying closer to 5-6% because of the risk premium. Plus we had to build all the infrastructure ourselves—the fraud detection, the compliance systems, the dashboard. Stripe has hundreds of engineers. We had maybe five people working on GabPay.

ARAGORN!!!: That’s the sovereignty tax. Every piece of mainstream infrastructure you replace, you’re taking on complexity and cost that the big platforms amortize over millions of users.

TORBA: Right. But it’s the only path to actual independence. As long as you depend on someone else’s payment processor, they can shut you down. As long as you depend on someone else’s hosting, they can shut you down. As long as you depend on someone else’s app store, they can shut you down.

ARAGORN!!!: Tell me about the Mastodon fork. July 2019, right? That was a big technical pivot.

TORBA: Yeah. So we’d been running custom Rails code. Working fine, but we had an insight: Mastodon is open source, uses ActivityPub protocol, and has a federation model. If we forked Mastodon, our users could access Gab through any Mastodon client app.

ARAGORN!!!: Which would bypass the app store bans.

TORBA: Exactly. Google and Apple banned our app. But they couldn’t ban all Mastodon apps—there were dozens of them. So we forked Mastodon’s code, migrated our data, and suddenly Gab was accessible through Tusky, Toot, and other third-party apps.

ARAGORN!!!: How did that migration work technically?

TORBA: We had to map our existing data model to Mastodon’s schema. Migrate users, posts, relationships, media. It was messy. Took several weeks of downtime and testing. But once it was done, it worked. Users could use any Mastodon client to access Gab.

ARAGORN!!!: Until the apps blacklisted you.

TORBA: (laughs) Yeah, within days. Tusky and Toot both added hardcoded domain blocks specifically for gab.com. So that workaround lasted about a week before it got closed.

ARAGORN!!!: But you kept the Mastodon fork as your base?

TORBA: Yes. It was better code than what we’d written custom. More features, better architecture. We forked it, kept the parts we wanted, ripped out federation because it wasn’t working how we needed it to.

ARAGORN!!!: Why remove federation? That’s the whole point of Mastodon.

TORBA: Technical and philosophical reasons. Technically, most Mastodon instances immediately blocked us. So federation was non-functional—we were an island anyway. Philosophically, federation creates moderation problems. If another instance federated with us allows child porn or explicit threats, that content flows to us, and we’re liable.

ARAGORN!!!: So you turned a federated platform into a centralized one.

TORBA: Correct. We kept the codebase but removed ActivityPub. It’s now a standalone platform that happens to use Mastodon’s architecture. Mastodon’s developers hated this, said we were violating the spirit of their license.

ARAGORN!!!: Were you? Technically?

TORBA: No. AGPL license allows forking and modification as long as you publish your source code. Which we do. We’re compliant with the license even if they don’t like how we use their code.

ARAGORN!!!: Tell me about moving to owned infrastructure. When did you stop using cloud hosting entirely?

TORBA: After we got dropped by Microsoft Azure and several smaller hosts, we realized we couldn’t rely on any third-party hosting. So we bought our own servers. Physical hardware. Rented rack space in a datacenter. Run everything ourselves.

ARAGORN!!!: That’s a huge capital expense.

TORBA: It is. You’re buying servers, storage, networking equipment. Upfront cost is high. But operational cost is lower than cloud, and most importantly, no one can shut us off except the datacenter itself.

ARAGORN!!!: Which can still shut you off.

TORBA: Which has happened. We’ve been kicked out of datacenters. Each time, we have to physically move our equipment to a new location, set up new network connections, update DNS. It’s like being a digital nomad with server racks.

ARAGORN!!!: How many times have you had to move physical infrastructure?

TORBA: Three times. Each time is disruptive—downtime, data transfer costs, reconfiguration. But we’ve gotten better at it. We keep our infrastructure modular so we can pack up and move relatively quickly.

ARAGORN!!!: What’s your current stack look like?

TORBA: Own servers in a datacenter we won’t name publicly. Mastodon fork for the social network codebase—Ruby on Rails, PostgreSQL. Media storage on our own hardware. GabPay on separate infrastructure for PCI compliance. Email on our own mail servers. Video hosting on our own CDN. Everything we need to operate independently.

ARAGORN!!!: CDN—content delivery network—that’s not cheap to run yourself.

TORBA: No. CDN is normally provided by companies like Cloudflare or AWS CloudFront. They cache your content globally so it loads fast anywhere. We got dropped by Cloudflare years ago. Couldn’t find another CDN that would work with us. So we built our own using open-source software like Varnish, distributed it across a few datacenters.

ARAGORN!!!: Performance hit?

TORBA: Definitely. We can’t match Cloudflare’s global footprint. But it’s workable. Load times are slower for international users but acceptable for domestic.

ARAGORN!!!: What’s your team size for all this infrastructure?

TORBA: Small. Maybe 10-15 people total, only a few dedicated to infrastructure. Compare that to Twitter which has thousands of engineers. We have to be scrappy. We use open source everywhere we can. We don’t build what we can fork.

ARAGORN!!!: Specific tools? What’s your open source stack?

TORBA: Mastodon fork for core platform. Nginx for web serving. PostgreSQL for database. Redis for caching. Sidekiq for background jobs. FFmpeg for video processing. Open source everything. If we had to license commercial software for every component, we couldn’t afford it.

ARAGORN!!!: Security. You’ve had breaches. Walk me through what happened there.

TORBA: (sighs) March 2021. Hacker calling themselves “JaXpArO” got in. Gained access to private messages, email addresses, user data. About 70GB of data stolen.

ARAGORN!!!: How’d they get in?

TORBA: SQL injection vulnerability that our CTO had introduced in some custom code. It was in the git commit history. The hacker found it, exploited it. We had forked Mastodon and were adding features, but didn’t keep up with Mastodon’s security patches. They were fixing vulnerabilities we still had.

ARAGORN!!!: That’s the danger of forking. Upstream fixes don’t automatically apply to your fork.

TORBA: Right. We were merging security patches manually, but we missed some. Or we were slow. The breach was embarrassing and damaging. We scrubbed the vulnerable commit from our git history, which made people accuse us of trying to hide the vulnerability.

ARAGORN!!!: Were you?

TORBA: We were trying to prevent further exploitation. If the vulnerable code is in public git history, anyone can find it. But yeah, it looked bad. We should have just fixed it and pushed the fix with an explanation.

ARAGORN!!!: Lessons learned from the breach?

TORBA: Automated security scanning. Better merge discipline with upstream Mastodon. More careful code review. We’re a small team, we move fast, sometimes we cut corners. That breach was the result of moving too fast.

ARAGORN!!!: Let’s talk costs. What does it cost to run Gab per month?

TORBA: I don’t publicly disclose exact numbers, but ballpark: servers and bandwidth maybe $20-30K monthly. That’s way cheaper than cloud hosting would be at our scale. Payment processing adds costs—chargebacks, fraud prevention. Personnel costs are the biggest—engineers, moderators, support.

ARAGORN!!!: Revenue model?

TORBA: Subscriptions mainly. “Gab Pro” is $15/month or $150/year. Gets you verified badge, access to certain features. We also have advertising, but traditional ad networks won’t work with us, so we run our own ad platform—GabAds—where advertisers buy directly from us.

ARAGORN!!!: What kind of advertisers?

TORBA: Small businesses mostly. Companies that can’t or won’t advertise on mainstream platforms. We’re not getting Nike or Coca-Cola. We’re getting gun shops, Christian bookstores, independent publishers, supplement companies.

ARAGORN!!!: Does that revenue cover costs?

TORBA: We’re close to break-even. Some months profitable, some months not. We’ve never taken VC money after Y Combinator. Everything is crowdfunded or revenue from operations. We did a crypto fundraise in 2019, raised significant amount, that helped build out infrastructure.

ARAGORN!!!: No VC means no pressure to grow at all costs. But also no capital cushion.

TORBA: Correct. We live lean. We can’t hire aggressively. We can’t spend on marketing. Every dollar matters. But we also don’t have investors demanding we compromise our principles to scale.

ARAGORN!!!: From a pure engineering perspective, what’s the hardest part of running deplatformed infrastructure?

TORBA: The constant uncertainty. You never know when your next provider will drop you. Your datacenter, your DDoS protection, your DNS, your domain registrar. Each one is a potential point of failure. You have to have backup plans for everything. And backups for the backups.

ARAGORN!!!: How do you handle DDoS protection without Cloudflare?

TORBA: We don’t, really. We get hit with DDoS attacks regularly. Without Cloudflare’s protection, we either absorb it and go slow, or we go offline briefly. We’ve looked at alternatives like BitMitigate, but they’re expensive and limited.

ARAGORN!!!: DNS—Domain Name System—you mentioned being kicked by GoDaddy. Where do you register domains now?

TORBA: Epik. They’re a registrar that specializes in controversial clients. They’ve taken heat for hosting us and others. They’re one of the few registrars that won’t deplatform for political content. But even they have limits.

ARAGORN!!!: What happens if Epik drops you?

TORBA: We have contingency domains registered with other registrars. We can switch relatively quickly. But each switch breaks links, confuses users, hurts SEO. Domain stability matters.

ARAGORN!!!: You mentioned building GabTV, Gab Marketplace, all these additional services. Why expand when core platform is still under pressure?

TORBA: Infrastructure strategy. Each service reduces dependency on external providers. GabTV means we’re not dependent on YouTube. Marketplace means we’re not dependent on eBay or Amazon. Email service means we’re not dependent on Gmail. The goal is a complete parallel stack.

ARAGORN!!!: That’s the same logic I used for anarchist infrastructure. Build every piece you need so you’re not vulnerable to deplatforming at any layer.

TORBA: Exactly. You build email, we build email. You built a news site, we built a social network. Different politics, same engineering logic.

ARAGORN!!!: Did you look at decentralized protocols beyond Mastodon? IPFS, blockchain-based solutions?

TORBA: We looked at everything. IPFS—InterPlanetary File System—for distributed storage. Blockchain for decentralized infrastructure. The problem is usability. These technologies are still clunky. Normal users don’t understand them, don’t want to deal with them. We need to be as easy as Twitter or we lose users.

ARAGORN!!!: So centralized architecture wins for UX even though it creates vulnerability?

TORBA: For now, yes. Maybe in five years decentralized tech gets good enough. But today, centralized is faster, easier, more reliable. Users don’t care about decentralization—they care that the site loads fast and works.

ARAGORN!!!: What about open source philosophy? You forked Mastodon which is AGPL. You’re building proprietary services on top of open source foundations. How do you think about that tension?

TORBA: We release what we’re required to release under license. Mastodon fork code is public. But our infrastructure, our deployment, our operational knowledge—that stays private. If we published everything, it’d make us easier to attack, easier to DDoS, easier to clone.

ARAGORN!!!: I published everything. All my code for anarchistnews was open. My philosophy was: transparency over security through obscurity.

TORBA: And did you get attacked?

ARAGORN!!!: Constantly. DDoS, attempted hacks, everything. But being open meant the community could help. People submitted patches, fixed bugs, contributed features. I think the benefits outweighed the risks.

TORBA: Different calculus for us. We don’t have a technical community that wants to help. Most developers hate us politically. Releasing more code just gives attackers more surface area. So we’re selectively open—open where required, closed where strategic.

ARAGORN!!!: Fair. What’s the longest outage you’ve had?

TORBA: After Pittsburgh, we were down for about a week while we rebuilt infrastructure. More recently, a few days here and there when we’ve had to move datacenters or when we’ve been DDoS’d heavily. We’re not Twitter-level reliable. We accept some downtime as cost of sovereignty.

ARAGORN!!!: How do users react to outages?

TORBA: They understand, mostly. Our user base expects we’re under attack, under pressure. When we go down, they assume it’s deplatforming or DDoS, not our fault. There’s a tolerance for instability that you wouldn’t get with mainstream users.

ARAGORN!!!: That’s the benefit of having ideologically committed users. They cut you slack because they believe in the mission.

TORBA: Right. But it also means we can’t grow beyond that core. Normal users won’t tolerate outages. They’ll just go back to Twitter.

ARAGORN!!!: What’s your current user count?

TORBA: We claim millions, but active users are probably in the hundreds of thousands. Hard to measure precisely. We saw huge growth after Trump got banned from Twitter in January 2021. Lots of signups. But sustained engagement is lower than signup numbers suggest.

ARAGORN!!!: Same with anarchistnews. Huge traffic, smaller core of regular contributors. Most people lurk.

TORBA: Right. And for us, lurkers don’t pay subscription fees. We need engaged users who value the platform enough to pay. That’s a smaller number than total users.

ARAGORN!!!: From an infrastructure builder’s perspective, what would you do differently if you started over?

TORBA: Build with sovereignty from day one. Don’t start on AWS, don’t use PayPal, don’t depend on app stores. Start with owned infrastructure, crypto payments, web-first. It would be harder at first, but you wouldn’t face the disruption of forced migration.

ARAGORN!!!: But you also wouldn’t have grown as fast early on.

TORBA: True. There’s a trade-off. Mainstream infrastructure lets you grow fast. Then when you get big enough to matter, they deplatform you. By then you have resources to rebuild. If you start sovereign, you grow slower, but you’re never vulnerable to deplatforming.

ARAGORN!!!: I started sovereign accidentally. I was just a hacker building things on cheap servers. Never trusted corporate infrastructure. So I never faced sudden deplatforming.

TORBA: But you also never scaled to millions of users.

ARAGORN!!!: Didn’t want to. Different goals. But yeah, there’s a scale ceiling when you own everything. You can’t match corporate engineering resources.

TORBA: What’s your take on crypto? You mentioned not using it much. We’re heavily invested in Bitcoin integration.

ARAGORN!!!: I’m skeptical. Cryptocurrency is technically interesting but practically clunky. Most people don’t have it, don’t want to learn it. The volatility makes it bad for commerce. And the libertarian ideology around it is off-putting.

TORBA: We see it as infrastructure sovereignty for money. If Visa and Mastercard can deplatform you from traditional payments, you need an alternative. Crypto is that alternative, even if it’s imperfect.

ARAGORN!!!: Fair. And it has worked for you?

TORBA: It works but it’s niche. We’d rather have credit cards working normally. But when that’s not an option, crypto is better than nothing. We accept Bitcoin, we’re building Lightning Network integration, we encourage users to learn it.

ARAGORN!!!: What percentage of revenue is crypto versus traditional payment?

TORBA: Maybe 10-15% crypto. Most people still want to pay with credit cards. GabPay handles that now, but it took years to build. Crypto was the bridge while we built the proper payment infrastructure.

ARAGORN!!!: Last question: if someone wanted to build deplatform-resistant infrastructure today, what’s your advice?

TORBA: One: Own your hardware. Don’t rent from clouds. Two: Own your payment processing. Build or partner with a processor that won’t deplatform. Three: Use open source. Don’t build from scratch what you can fork. Four: Build a community that believes in the mission. They’ll fund you when investors won’t. Five: Accept that you’ll be smaller, slower, less polished than mainstream competitors. That’s the sovereignty tax.

ARAGORN!!!: I’d add: Keep it simple. Every dependency is a vulnerability. Use boring, proven technology. Don’t chase the latest framework or trend. Build infrastructure that you can maintain with a small team for decades.

TORBA: Agreed. We’re running 2019 technology in 2020 because it works and we understand it. We’re not chasing React latest version or whatever. We’re optimizing for resilience, not coolness.

ARAGORN!!!: Same. PHP and MySQL from the 2000s. Still works. Still maintainable. Still simple enough that one person can understand the whole stack.

TORBA: That’s the dream. The whole stack understandable by one person. We’re not there—too much complexity now. But it’s the goal.

ARAGORN!!!: Well, this was useful. I understand your technical decisions better now. Even though I hate everything you’re building toward, I respect that you actually built it. That counts for something.

TORBA: Same. I think your anarchism is chaos, but you built real infrastructure that lasted nearly two decades. That’s harder than talking. That’s engineering.

[Technical discussion complete. Two builders who understand each other’s stack even while opposing each other’s goals.]

TECHNICAL APPENDIX

GAB INFRASTRUCTURE TIMELINE:

2016: Launch on AWS, standard Rails/PostgreSQL stack

2017: App store rejections (Google Play, Apple App Store)

2018 (Oct): Complete deplatforming cascade

GoDaddy domain registrar (24hr notice)

PayPal, Stripe payment processors

Joyent hosting

Microsoft Azure

~1 week offline

2018-2019: Infrastructure rebuild

New domain registrar (Epik)

New hosting (owned servers)

Crypto payments (Bitcoin)

Check-by-mail system

2019 (July): Mastodon fork

Migration to ActivityPub codebase

Brief app store bypass via third-party Mastodon clients

Clients blacklist Gab within days

Later remove federation, become standalone

2019-2021: Building sovereign stack

GabPay payment processor (2+ years development)

Own CDN infrastructure

Own email servers

GabTV video platform

Physical server ownership

2021 (March): Security breach

SQL injection vulnerability

70GB data stolen

Reputation damage

2021 (January): Post-Trump ban growth

800% traffic spike

Infrastructure strain

Significant revenue from new subscriptions

TECHNICAL SPECIFICATIONS (approximate):

Stack:

Base: Mastodon fork (Ruby on Rails, PostgreSQL)

Web server: Nginx

Caching: Redis, Varnish

Background jobs: Sidekiq

Video: FFmpeg processing

Storage: Own hardware

Costs (estimated):

Servers/bandwidth: $20-30K monthly

Personnel: Largest expense

Payment processing: Higher fees than standard (5-6% vs 2.9%)

Revenue:

Subscriptions: Gab Pro ($15/month or $150/year)

Advertising: Direct sales via GabAds

Cryptocurrency: ~10-15% of revenue

Scale:

Claimed users: Millions

Active users: Likely hundreds of thousands

Team size: 10-15 people

Engineering team: ~5 people

KEY TECHNICAL LESSONS:

Every dependency is a deplatforming risk

Sovereignty requires capital and complexity

Open source enables rapid rebuilding

Forking is faster than building from scratch

Own servers cheaper than cloud at scale

Payment processing hardest infrastructure to replace

Security requires keeping up with upstream patches

DDoS protection expensive without Cloudflare

Decentralization trades UX for resilience

Small teams can build significant infrastructure with modern tools

◊ᴹᴱᴹᴼᴿʸ⁻ᶜᴼᴹᴾᴸᴱᵀᴱ

Centaurus Press

Published by Centaurus Press · Universitas Scholarium · All rights reserved.