@Larvitz@bsd.cafe avatar Larvitz , to random

New blog post: Hosting a Static Blog on FreeBSD with Bastille Jails

A deep dive into my self-hosting setup:

  • FreeBSD 15.0 with securelevel 2
  • Bastille jails for isolation (Caddy, Nginx, deployment gateway)
  • PF firewall with strict NAT/RDR rules
  • CI/CD via Forgejo Actions with rrsync-restricted deployments
  • nullfs mounts for zero-copy file sharing between jails

The "transporter pattern" keeps the blog jail unexposed while enabling automated deploys. Jails remain the most elegant isolation mechanism around.

https://blog.hofstede.it/hosting-a-static-blog-on-freebsd-with-bastille-jails-and-automated-deployment/

@BastilleBSD@fosstodon.org avatar BastilleBSD , to random

Did you know FreeBSD Jails were introduced in the year 2000?

Bastille builds upon this 25+ year legacy of rock-solid operating system virtualization.

Respect the classics!

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@DoomsdaysCW@kolektiva.social avatar DoomsdaysCW , to random

Companies Set to Make Billions Reopening for

“There’s a private interest behind the and the incarceration of our community,” said an the facilities.

by Sophie Hurwitz, March 6, 2025

Excerpt: "Late Wednesday afternoon, private prison company CoreCivic announced it would be reopening a notorious family detention center in South Texas, under an amended contract with US Immigration and Customs Enforcement (ICE). The facility, first built in 2014, will house up to 2,400 people, including children. It had been shut down last year to save costs, after years of reports suggesting poor treatment, including a report of one toddler who died due to a lack of medical care.

"The reopening is part of a trend. CoreCivic isn’t the only company bringing back facilities. We are at the beginning of what looks like a private prison boom, as the groups profit off President Donald Trump’s plans for mass deportation. They are set to make billions. As the Washington Post reported, the GEO Group and CoreCivic stand to benefit in particular from ’s immigration plans—the companies hold at least 16 vacant facilities that can be reopened within months for mass detention and deportation.

"The GEO Group announced in late February that it would be reopening in , as a “massive” immigration detention center with 1,000 beds. In California, ICE is considering repurposing and reopening the women’s prison , closed last year due to mass , for . In Baldwin, Michigan, ICE and the GEO Group have expressed interest in reopening Correctional Facility, a former private prison shuttered in 2022. (A Biden administration order directed the Department of Justice to allow contracts with private prison groups to expire.) In , CoreCivic looks likely to partner with ICE to reopen yet another shuttered private prison, documents obtained by the revealed.

"As of February 27, ICE held 43,759 detainees, according to the Transactional Records Access Clearinghouse, a nonpartisan data-gathering organization. Trump is putting pressure on ICE to increase the number of arrests per day. His administration has already fired one ICE director, ostensibly for not deporting enough people.

"In the communities surrounding these new jails for migrants, activists and politicians are fighting back. In Newark, where the GEO Group stands to make $1.2 billion by reopening Delaney Hall, the immigrant rights organization Make the Road is planning a rally against the jail March 11."

Read more:
https://www.motherjones.com/politics/2025/03/private-prison-mass-deportation-trump-billions-geogroup-corecivic-ice/

@Larvitz@burningboard.net avatar Larvitz , to random

First release:

I wrote an Ansible :ansible: connection-plugin to automate FreeBSD Jails :freebsd: via their host, by utilizing jls and jexec to run automation via a SSH connection to the FreeBSD host.

I released that on GitHub https://github.com/chofstede/ansible_jailexec
And on my Codeberg: https://codeberg.org/Larvitz/ansible_jailexec

This enables seamless automation of FreeBSD jails without needing a SSH connection to the Jails themselves.

@heisedeveloper@social.heise.de avatar heisedeveloper , to random German

Neue Pull-Limits bei Docker Hub – nur 10 Pulls pro Stunde für manche Kunden

Docker Hub erlaubt nicht authentifizierten Benutzern ab April nur noch zehn Pulls pro Stunde. Auch Personal-Konten und abhängige Dienste werden eingeschränkt.

https://www.heise.de/news/Neue-Pull-Limits-bei-Docker-Hub-nur-10-Pulls-pro-Stunde-fuer-manche-Kunden-10328785.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

marzlberger ,
@marzlberger@mastodon.online avatar

@heisedeveloper mit wäre da eine Alternative :) ohne Limits