How to Harden Services on FreeBSD with Capsicum
How to adapt a FreeBSD program for Capsicum by pre-opening resources, limiting descriptor rights, entering capability mode, and testing denial.
Step-by-step, task-oriented guides — do this, in this order, to get this result.
How to adapt a FreeBSD program for Capsicum by pre-opening resources, limiting descriptor rights, entering capability mode, and testing denial.
How to configure modern FreeBSD CARP on two hosts, control election and preemption, test failover, synchronize PF state, and monitor HA.
A production-safe FreeBSD DTrace workflow for loading providers, narrowing probes, aggregating syscalls and stacks, and controlling tracing overhead.
A current iocage workflow for selecting a supported FreeBSD release, creating a ZFS-backed jail, managing networking, updates, snapshots, and removal.
How to build and verify multiple FreeBSD routing tables, assign services and jails to FIBs, use PF policy routing, and distinguish them from MPTCP.
How to design a resilient FreeBSD ZFS NAS, configure a supported Samba package, align identities and permissions, and verify backup and client access.
A secure FreeBSD pkg repository workflow covering package provenance, offline signing, atomic publication, HTTPS serving, client trust, and rollback.
A reproducible Poudriere workflow for supported FreeBSD build jails, pinned Ports trees, reviewed options, signed repositories, client tests, and upkeep.
A console-safe FreeBSD IPv4 router and PF NAT workflow covering interface plans, forwarding, default-deny rules, management access, validation, and recovery.
Build and test a Haiku backup that preserves BFS attributes, user settings, package inventory, writable state, and safe restore boundaries.