// the find
matze/wastebin
wastebin is a pastebin 📝
wastebin is a self-hosted pastebin written in Rust on axum and SQLite, shipped as a single binary and a small scratch-based Docker image. It suits anyone who wants a paste service on their own machine for logs, snippets or config fragments without running more than one process to get it.
Storage is one SQLite file with zstd-compressed paste bodies, so a deployment is a binary plus a file, and the schema evolves through numbered SQL migrations rather than an ORM layer. Raw HTML in Markdown pastes goes through the ammonia sanitizer, and the Content Security Policy stays strict on every route except /md/, where external images are allowed. Owner tokens let you delete pastes without an account, and the README says plainly that a reused token is a shared credential, which is the honest way to document it. wastebin-ctl can list, purge and delete entries directly against the database, which helps when the web UI is the wrong tool.
The README is clear that there is no authentication and no DoS protection, so exposing it publicly means putting a reverse proxy with rate limiting in front, and that is one more piece to maintain. Some defaults will bite you. The database path defaults to :memory:, so pastes vanish on restart unless WASTEBIN_DATABASE_PATH is set. WASTEBIN_PASSWORD_SALT falls back to the fixed string somesalt, so every instance that does not override it hashes encryption passwords with the same salt. The signing key is random per start by default, which means owners lose the ability to delete their pastes after any restart. Encryption protects the database file but not the content from whoever runs the server, because the server receives the plaintext and the password on every request. A single SQLite writer is fine for a personal instance, but it is a ceiling if the service ever gets real traffic.