Mastodon

Welcome to Larvitz Blog! I’m Christian, a Senior Consultant by day and FreeBSD enthusiast by night, with over 20 years in enterprise IT. Here I write about FreeBSD jails, PF firewalling, self-hosting, Linux system administration, and anything that’s cleanly engineered. Most articles are hands-on guides born from running my own infrastructure, from dual-stack networking and Ansible automation to hosting a Mastodon instance on FreeBSD.

Have a question or want to discuss something? Find me on the Fediverse at @Larvitz@burningboard.net. I’m always happy to chat!

Articles


Claude Code on a FreeBSD Desktop: Plasma, xrdp, the Linuxulator and One Very Confusing PATH

A FreeBSD 15.1 Plasma desktop in a Proxmox VM, reachable over xrdp, running Claude Code as a Linux binary through the Linuxulator. Along the way: an Xorg that found no screens, a KRDP package that does not exist, a VirtIO-GPU that gives you a framebuffer but no acceleration, and a “version regression” that turned out to be two Claude installations fighting over my PATH. Then I let the agent firewall the machine it was running on, and it did that more carefully than I usually do. It also got one thing wrong, and of course it was the thing about root.

FreeBSD Foundationals: rc.d - The Service Framework That Fits in Your Head

The fourth in the FreeBSD Foundationals series. This one picks up where the boot article stopped, at the moment init runs /etc/rc. It covers how rc finds and orders scripts with rcorder, how rc.conf and its layers are really just shell, what rc.subr gives you for free, how to drive it all with service and sysrc (including inside jails), how to write a correct rc.d script for your own daemon using daemon(8) supervision, and the pidfile trap that makes “service stop” restart your process instead of stopping it. Then an honest audit of the rc.d scripts running my own Mastodon, Zigbee2MQTT and NetBox jails. Plus service jails, debugging, and an honest comparison with systemd units.

  • Sat 03 October 2026
  • Linux

Self-Hosted AI: Qwen 3.8 on a Rented Blackwell at 150 Tokens per Second

An open-weight Qwen 3.8 27B model, an RTX PRO 6000 Blackwell rented by the hour, and one shell command to start it. For most of my everyday coding it is good enough, it answers at roughly 150 tokens per second, and my prompts stay on infrastructure I chose. Some honest caveats about what “self-hosted” means on someone else’s GPU are included, along with the workflow that has worked best for me: a frontier model for architecture, and a fast open-weight model for the token-heavy implementation loop.

My Ansible Plugin Had a Jail Escape: CVE-2026-55074

For almost a year, my jailexec connection plugin let a compromised FreeBSD jail redirect a root-owned write onto the jail host. The input validation was fine. The problem was on which side of the jail boundary the paths were resolved. This is the story of the bug, the fix in 2.0.0, and the CVE that came with it.

  • Thu 17 September 2026
  • Linux

No Proxmox Backup Client for RHEL? Hold My Container Runtime

RHEL 10 on ARM64, a Proxmox Backup Server, and no convenient native client package. I borrowed the client from an old server container, mounted the host root filesystem read-only, and gave SELinux a very specific explanation. Five minutes later, I had an encrypted, incremental backup. There are caveats.


Bespoke: A Programming Language for People Who Say Please

Modern programming languages are full of violence, vulgar abbreviations, and naked imperatives. Bespoke is a statically typed alternative in which exceptions are regrettable circumstances, mutexes grant private audiences, and every request to the compiler ends with a proper thank-you.

  • Thu 03 September 2026
  • Linux

Running Citrix Workspace on Fedora with Rootless Podman

Citrix Workspace is an application I need but do not want woven into my workstation. I put its official Debian package in a disposable rootless Podman container, then pass through just enough X11, PipeWire, GPU, and webcam plumbing to open downloaded ICA files from Fedora’s file manager.

I Wanted an IPv4 Toast and Accidentally Built an IP Service

At 10:15 this morning I added a gently condescending toast for IPv4-only visitors to hofstede.it. It called ipify, which felt increasingly inappropriate for somebody operating an ASN. Three hours later I had written a Rust IP-information service, put it behind Caddy, given it three DNS names, and deployed it in its own dual-stack FreeBSD VNET jail. This is how a two-line dependency became infrastructure.

bhyve Inside a Jail: The FreeBSD Feature Nobody Uses

A jail shares the host kernel, so sooner or later you need a real virtual machine. bhyve has been able to run inside a jail since FreeBSD 12.0, and almost nobody does it. This is the full build from my production hypervisor: the devfs ruleset, the four things that have to line up, the two-tier bridge topology, and an honest account of what allow.vmm does and does not buy you.