Using MaxMind’s GeoLite2 database with FreeBSD’s PF firewall to restrict client-facing services to specific countries, reducing brute-force attempts and log noise while keeping essential services globally accessible.
A full-stack overview of hosting a Pelican blog on FreeBSD 15.0 using Bastille jails, Caddy reverse proxy, and automated CI/CD deployment via Forgejo Actions.
Migrating a Mastodon instance to FreeBSD with BastilleBSD - a multi-jail architecture with aggressive service separation, centralized PF firewalling, and a fully dual-stack network design.
A reproducible dual-stack configuration for FreeBSD on Hetzner Cloud with VNET jails, PF NAT for IPv4, and a /65 split trick to give jails native globally-routable IPv6 from a single /64.