-
kerneldove
for a jail that doesn't have a public ip, and only has a private lan ip, i guess i don't set a default gateway address?
-
kerneldove
or do i make the jail host be the default gateway or? how do i know pls?
-
sig`
depends if the jail has its own network stack
-
kerneldove
ya it's vnet
-
sig`
on the host check, jls -N
-
sig`
and jexec nameofjail ifconfig
-
kerneldove
ok you're just telling me commands but WHY
-
kerneldove
like what's the point
-
sig`
it either shares the hosts network or has its own
-
kerneldove
i said it has vnet
-
sig`
my bad that you said vnet already, so the only thing left is what the jails epair is pluggeed into the host thats what decides the next hop
-
sig`
is your nic a physical member?
-
kerneldove
don't even know what your'e asking or why. i'm back at the conceptual stage. if a jail is only intended to have a private lan ip, it doesn't get a default gateway address configured right?
-
sig`
kinda rude for someone trying to help your vague question
-
kerneldove
agree to disagree
-
sig`
good luck
-
kerneldove
ya helping ppl usually involves actually reading their question and understanding what their goal is instead of just blurting shit out
-
sig`
ok, well you'll find what you're looking for eventully. need to remember that some people do this for a living.
-
sig`
later
-
sig`
for the record, public vs private has nothing to do with it. What matters is whether traffic actually leaves the subnet and pkg, dns, ntp all do so yes it gets a default gateway and since it's 'VNET' with its own routing table you set it in the jail ' defaultrouter="yourlanrouter", same address every other box on that lan uses.
-
sig`
the epair/bridge stuff i was asking about only matters if your setup isn't the simple bridged case. Which I was trying to establish...
-
kerneldove
jail uses host time so ntp is irrelevant afaik. pkg for the jail is also ran by the host. and there's no dns. this is all so that jails can be on a private lan, doing specific work in a service-oriented architecture, behind another jail that does have a public ip and proxies to the others on the private lan
-
sig`
yeah if the private jails only ever talk to the proxy jail on the same subnet then no default route needed at all. Now we know that nothing leaves the subnet. Also pkg -j runs pkg inside the jail, so with vnet it uses the jail network and dies with no route. use pkg -r /path/to/your/jail/ so the host fetches. If the proxy jail is on a diff subnet then the privat ones they do need a route back to it. static or default either way.
-
mason
Oh, I need to think about that. I've set up NAT so I could reach out from my jails, but maybe I don't actually need it.
-
kerneldove
pkg -r
-
kerneldove
proxy jail has 2 epair nics. 1 with public ip and 1 with ip on private lan
-
kerneldove
mason ya i'm converting my jails to not need internet by default by using freebsd-update -j and pkg -r
-
mason
nice nice
-
mason
I've said this in here before, but my latest move is off of epair/vnet and onto old-fashioned networking for jails. I'm loving it.
-
mason
I think the next move for me would have to be off of jails entirely and back to chroots. :P
-
kerneldove
why and how?
-
mason
Why? Simplicity. How? I spin up a new lo interface for them to sit on, with a private subnet, and then just port forward in as needed, and NAT out, although clearly the NAT is optional.
-
kerneldove
ya that's cool. i'll still keep using vnet except for service jails that are just app containment but i see the value
-
kerneldove
so i got a jail host and vnet jail with no public ip, only private ip. i want to ssh to jail host port 555 and have it redirect to the jail's private ip and port 22. on jail host i made pf rule `rdr pass on pubif proto tcp from any to any port 555 -> 192.168.0.5 port 22` then it says blocking from bridge0 to 192.168.0.5, so i add pass on bridge,
-
kerneldove
reload pf, now i ssh to jail host port 555 but nothing happens. what i'm doing wrong pls?
-
kerneldove
i don't have a nat rule set maybe that's it? also don't have a default gateway set for jail
-
mason
kerneldove: I'd personally just ssh with the host as a proxyjump.
-
spork_css
personally I never use VNET jails unless there's a true need for it - feels overly-complicated. no epairs, no bridges, just an alias on the host and you can do that even if you have an int and ext network on two ports on your host.
-
bsdrobert
it is complex, thats why you automate it so it becomes simple, but generally agreed.
-
kerneldove
working on automating it now
-
kerneldove
i want vnet for max security because i'm giving jails out to friends as virtual freebsd systems
-
mason
Complexity as in many moving parts, more than anything. Fewer moving parts == good.
-
mason
Anyway, g'night.
-
kerneldove
well i had a perfect configuration for jails that have their own public ip (and private ip) i'm switching now to not requiring jails to have a public ip so that requires quite a bit of chnages. i'll hammer on that and eventually get it solid too
-
bsdrobert
my goal is to eventually take the 'anonssh' program I wrote and turn it into 'minijail', so you can launch any program in a jail and only include that programs dependencies. So much less than base. A single user, maybe root. It already works but is tighly coupled to launching sshd in a jail rather than any program.
-
kerneldove
is there any value in putting different groups of jails on different bridges? like to isolate jails from 1 user from jails of another user?
-
ForeverNoob[m]
Are these the strongest GELI settings? geli init -e AES-XTS -l 256 -a HMAC/SHA512 -s 4k /dev/disk
-
dkeav
yes
-
ForeverNoob[m]
yay!
-
polarian
ForeverNoob[m]: pretty sure thats default though :p
-
polarian
also isn't AES-XTS vs AES-CBC still disputed? :p
-
boru
XTS is for data at rest. CBC is for data in motion.
-
polarian
I will be holding a FOSS meetup in London on the 8th August, if you are interested please PM me for details!
-
polarian
I dont think there is any ML I can really put it on for freebsd
-
polarian
so the IRC will have to do
-
ForeverNoob[m]
Would if I could!
-
ForeverNoob[m]
-
ForeverNoob[m]
Overwriting 4x 16TB drives with /dev/random is going to be a "fun" experiment in patience.
-
kerneldove
is there any value in putting different groups of jails on different bridges? like to isolate jails from 1 user from jails of another user?
-
dkeav
thats not a jail issue, thats a network design issue
-
dkeav
VNET jails for example would already have their own interface
-
kerneldove
dunno what any of that meant. the question is, put all jails for different people on the same bridge, or put jails for each person on their own bridge
-
dkeav
-
kerneldove
?
-
kerneldove
ok got ssh into jail without public ip working using port forwarding
-
mason
kerneldove: Might be simpler still to use ProxyJump.
-
mason
kerneldove: Advantage: you're not exposing additional SSH ports.
-
mason
That said, locking that down to just individual users and not letting them connect to the host itself or to other jails might be difficult.
-
kerneldove
well simpler isn't my #1 priority. dunno what proxyjump is but i got this working with just base fbsd functionality. pf, vnet jails, bridges
-
IamThatIam
I am at a point where I am a hair distance from switching to FreeBSD in the future
-
IamThatIam
I am noticing the political front in the linux community and it isn't for me. I like the non-woke distros but even they seem to be politica
-
IamThatIam
I just refuse to participate in all of that
-
IamThatIam
also I don't support Linus Torvalds woke agenda and his membership to the WEF
-
IamThatIam
he is a globalist
-
IamThatIam
I'm not for that either
-
IamThatIam
I support Slackware's ideology
-
IamThatIam
currently I am using Devuan but eventually Debian will sabotage that because they have the common liberal leftist globalist ideology
-
IamThatIam
they will do it because it is their code base and Linus will put AI in the kernel like copilot and very soon Bill Gates and M$ will own linux
-
Reinhilde
If you're going to be like this, openly, and unapologetically, to a significant subset of FreeBSD's users, just leave. Your behaviour does not appear conducive to the desired environment.
-
IamThatIam
well I am saying this. FreeBSD is NOT linux
-
IamThatIam
it is a separate OS
-
IamThatIam
they are NOT the same thing
-
IamThatIam
linux is a kernel
-
Reinhilde
See points 2 and 3 of the topic's first section: be civilised, and respect others
-
IamThatIam
FreeBSD is an OS
-
IamThatIam
I will be civilized but I am not going to tolerate bullies of any type
-
IamThatIam
that's just how it is
-
IamThatIam
I don't have to
-
Reinhilde
I don't see how praising "non-woke" and "anti-woke" is respecting others when "woke" is comprised of a single proposition: injustices can be combatted
-
mewt
seems rather unrelated to the OS either way...
-
IamThatIam
well it is like this... I am not about politics. I am about what is actually true. I've spent the last 10 years doing research and I mean real research and not media research and not just believing things I am told.
-
IamThatIam
I am not saying that everyone does this
-
Reinhilde
I proffer that you're an agent-provocador from casa de Lunduke.
-
IamThatIam
there are tons of people in Europe who are well aware and making the same decisions
-
mewt
yeah I dunno, if you like freebsd use it
-
IamThatIam
no it isn't even that I support Lunduke. I think for myself
-
IamThatIam
not a lemming
-
IamThatIam
mewt, FreeBSD looks pretty good
-
mewt
but this is not really related to...well...the OS at all
-
Reinhilde
lotta folks, mostly men, have told me that. 0% of them actually do think for themselves
-
IamThatIam
it isn't
-
IamThatIam
I thought I joined the offtopic chan
-
IamThatIam
lol
-
IamThatIam
anyway fair point
-
Reinhilde
forewarned is forearmed, your behaviour is also not conducive to the desired enviroment over in -social
-
mewt
this and the "prove to me I should switch to your distro/OS" in what is nominally a support channel is tiring after a while
-
IamThatIam
Reinhilde, I take your "forewarnings" as threats
-
Reinhilde
Take them thus, if you like. I'm not here to implant a mode of thinking into you, you seem to have plenty of people like that for you already.
-
IamThatIam
I am civil but once again not a serf
-
» Reinhilde ## A quiet "plonk" rings out in the distance.
-
IamThatIam
the point I make is very simple. People want privacy, they want control over their OS, they want freedom with what they do with their OS and then they submit to the people who do not want them to have it. The entire thing is about money
-
IamThatIam
it should be FOSS
-
IamThatIam
not politics
-
IamThatIam
I like FreeBSD's design and license so far from what I am seeing
-
IamThatIam
I notice that its community is not about politics ( or shouldn't be because they are not the linux community )
-
IamThatIam
mewt, you don't have to prove to me why I should switch to FreeBSD. The behavior of many people are already doing that
-
IamThatIam
I am enjoying Devuan but I see this as a temporary situation perhaps. It is a matter of time until that situation implodes on all debian based distros and I will be forced to either migrate to slackware, freebsd, or another bsd-like distro
-
mewt
*plonk: the sequel*
-
IamThatIam
so anyway. I do apologize for this not being the offtopic channel and I will take note in the future
-
IamThatIam
I will be leaving now as I am unwelcome even by the nonpolitical
-
Reinhilde
unlike this nimrod, I am well aware of the fact that FOSS and communities around it are an explicitly political project.
-
Reinhilde
(thankfully the nimrod left the channel.)
-
mewt
guess it really was just looking for reactions
-
Reinhilde
it as in their behaviour I suppose?
-
mewt
yes
-
kerneldove
not very welcoming
-
dnp1
It was very #freebsd-social
-
wcarson
updating one of my ec2 instances from 15.0 to 15.1 and i'm at the step of updating the bootloader, however the freebsd-boot partition is only 16K and is not large enough for gptboot... any ideas? :/
-
wcarson
it seems to have booted just fine into 15.1-RELEASE so.. idunno, nothingburger? heh
-
mason
wcarson: They're legacy then?
-
wcarson
what do you mean by legacy?
-
» spork_css puts on off-topic hat
-
spork_css
I find many people that speak at length about "doing their own research" end up being very Dunning-Kruger
-
mason
spork_css: There's actual #freebsd-social for this, FWIW. I don't see you in there, but it's the Right Place.
-
mason
I have more commentary for there if you join it.
-
spork_css
just a throwback to our wanderer that left...
-
mason
Yeah.
-
spork_css
speaking of that, bouncers besides znc that people like, because this setup for an irc newb is both too GUI and not GUI enough, if that makes sense.
-
mason
spork_css: Here, it's just irssi on a host that stays up and connected, and I ssh into it.
-
spork_css
maybe I need to give myself a little shove with znc here and see if I can convince it to join -social with only sending commands to it via this irc app (Textual on macos, fork of LimeChat, FWIW).
-
mason
Hm. ZNC has always seemed daunting here.
-
mason
Maybe if you get it to work, you can write up what you did...?
-
r0ni
spork_css: if you are connected to your znc from textual if you join a channel it should just save it and join next time as well
-
r0ni
remember textual is actually connected to your znc and not just plain irc so what you send it, you send to znc
-
spork_css
I've been configuring "join list on start" via znc, and thinking that's the only way to do it, but I just right-clicked on the Libera (via znc) network and there was a "list channels" - and I clicked -social and there I am. Man...
-
spork_css
I setup znc years ago just for all the scrollback features plus the general urge to not connect directly from home and just never dug in to it.
-
r0ni
mines setup to just pull up everything on my znc, but i've not changed a conf manually in over a decade by now, i'd have to re-learn it all to change anything
-
mason
I've taken to leaving keywords in files I search (really a database, but...) for things I do periodically and forget. So I document them and then search as needed. Some of this makes it onto various wikis.