Social Media Pattern

Bluesky PDS

Your identity. Your AWS account. Nobody else's PDS.

A production-ready Bluesky Personal Data Server in your own AWS account in about 20 minutes — full ownership of your AT Protocol identity, configured the way an AWS consultancy would do it for an organization that can't risk losing its account.

Deploy on AWS Marketplace →
Who This Is For

Own Your Identity on the AT Protocol

Media Organizations

Owned identity infrastructure that no platform can suspend.

AT Protocol Developers

A real PDS to build and test against, running on your own account.

Privacy-Focused Individuals & Orgs

Full control of your cryptographic keys and identity.

Open Source Projects

Federation-ready identity without depending on a hosted provider.

Journalists

Guaranteed account portability — nothing to lose if terms change.

Custom-Domain Organizations at Scale

Manage many verified handles under infrastructure you control.

If losing access to your account would mean losing your audience, the next section explains what you're actually trading for free hosting.

Why Pay At All?

What $0.02/hr Actually Buys You

Bluesky's official hosting at bsky.social is free, so this isn't a cost comparison — it's a question of what you're trading for that free hosting: your cryptographic keys, your infrastructure, and ultimately your control over your own identity on the network.

You Hold the Keys

Cryptographic key ownership lives in your AWS account, not a third party's infrastructure.

Guaranteed Portability

Your identity and data live where you control them — nothing to migrate if a hosted provider changes terms.

Same Federation, Your Infrastructure

Full access to the AT Protocol network, just running on infrastructure you own.

$0.02/hr WHAT INDEPENDENCE COSTS

About $14.60/month for full ownership of your identity infrastructure — compared to $0 for hosted, but with a third party holding your keys.

Why Self-Hosted

Self-Sovereign Identity on the AT Protocol

Bluesky PDS is free and open source. Running your own instance means your cryptographic keys and identity live in infrastructure you control — not a third party's, even a well-intentioned one.

Free & open-source, no license fees

Full federation with the Bluesky network

Your keys and identity stay in your infrastructure

Guaranteed portability, no vendor lock-in

What This Pattern Handles For You

Production-Ready, Following AWS Best Practices

This CloudFormation template and custom AMI deploy a complete Bluesky PDS environment — live in about 20 minutes.

Self-Sovereign Identity

Control your own data and identity on the AT Protocol.

Federation Ready

Connect to the broader Bluesky network.

AWS Best Practices

Built with security and scalability in mind.

Infrastructure as Code

Deploy using CloudFormation with full visibility.

Live in about 20 minutes
The Direct Comparison

What's Easy to Get Wrong, Handled By Default

Obstacles to Deployment Without FOSSonCloud Pattern
Solved By FOSSonCloud Pattern
Obstacle Without FOSSonCloud Pattern

Implementing the AT Protocol server correctly

Solved By FOSSonCloud Pattern

A maintained, versioned AMI running the current PDS release

Obstacle Without FOSSonCloud Pattern

Managing cryptographic key security properly

Solved By FOSSonCloud Pattern

AWS managed keys and Secrets Manager encrypt data at rest and in transit

Obstacle Without FOSSonCloud Pattern

Setting up DID and domain verification

Solved By FOSSonCloud Pattern

VPC network isolation and least-privilege IAM access, configured by default

Obstacle Without FOSSonCloud Pattern

Debugging federation and crawling issues

Solved By FOSSonCloud Pattern

CloudWatch monitoring and logging, built in from day one

Built By People Who Do This Professionally

FOSSonCloud is built by Ordinary Experts, an AWS Consulting Partner working in Infrastructure as Code since 2014. This isn't a repackaged black-box AMI — the CloudFormation template is open source, so you can see exactly what's being deployed.

Architecture

Bluesky PDS architecture diagram showing the AWS infrastructure components

This pattern deploys a complete Bluesky PDS infrastructure including:

  • EC2 instances with auto-scaling
  • S3 for blob storage
  • CloudWatch for monitoring and logging
  • VPC with proper network isolation
Before You Start

What You'll Need

Everything required to go from this page to a running Bluesky PDS deployment.

An AWS Account

With billing enabled and permission to launch resources in the region you plan to deploy to.

A Subscription to This Pattern on AWS Marketplace

Accepting the marketplace terms is what makes the CloudFormation template available to launch in your account.

A Registered Domain Name

Needed to configure your PDS domain and SSL certificates, and for DID verification on the AT Protocol.

IAM Permissions to Launch CloudFormation Stacks

The stack creates EC2 instances, an S3 bucket, and CloudWatch monitoring on your behalf, using least-privilege IAM roles and Secrets Manager for key storage.

About 20 Minutes

For the stack to finish launching before you can start federating.

Getting Started

Up and Running in 4 Steps

1

Subscribe to the Bluesky PDS pattern on AWS Marketplace

2

Launch the CloudFormation stack in your AWS account

3

Configure your domain and SSL certificates

4

Start federating with the Bluesky network — live in about 20 minutes

Support Included

Self-Hosted Doesn't Mean Unsupported

Free Onboarding Session

A 1-hour call with a FOSSonCloud engineer, included with every deployment.

Ongoing Email Support

Direct line to support@fossoncloud.com whenever you need it.

Deploy on AWS Marketplace

Production-ready Bluesky PDS in your own AWS account, live in about 20 minutes.

Deploy on AWS Marketplace →