Here's a gist if you need to figure out which veth device to run tcpdump against.
gist.github.com/amf3/ca6b910...
Here's a gist if you need to figure out which veth device to run tcpdump against.
gist.github.com/amf3/ca6b910...
It turns out you need M3 or newer Apple Silicon for nested virt. Womp-womp …
It turns out you need M3 or newer Apple Silicon for nested virt. Womp-womp …
Instead of writing a new post, I updated my existing tips and tricks with Busybox.
amf3.github.io/articles/vir...
Instead of writing a new post, I updated my existing tips and tricks with Busybox.
amf3.github.io/articles/vir...
For just_enough minimal containers, I'd say 3-5 minutes. Long enough for me to either extract the SBOM from the container image or to click the #buildroot project link on gitlab.
github.com/amf3/just_en...
For just_enough minimal containers, I'd say 3-5 minutes. Long enough for me to either extract the SBOM from the container image or to click the #buildroot project link on gitlab.
github.com/amf3/just_en...
#selfhosted #docker
#selfhosted #docker
lemire.me/blog/2026/06...
lemire.me/blog/2026/06...
* Control the build pipeline, control the artifact.
* Declaritive image contents are the goal. Small image sizes are a byproduct.
* Stop waiting for vendor patches. Update the base git hash & rebuild.
Resulting in a 51MB #Python flask app.
* Control the build pipeline, control the artifact.
* Declaritive image contents are the goal. Small image sizes are a byproduct.
* Stop waiting for vendor patches. Update the base git hash & rebuild.
Resulting in a 51MB #Python flask app.
"/bin/busybox --install -s /bin"
Screenshot is an example Dockerfile showing how this is done.
"/bin/busybox --install -s /bin"
Screenshot is an example Dockerfile showing how this is done.
Today I got OCI image attestation working on an Unbound DNS container build. Seeing provenance attached from build system to container image feels like a big milestone.
Today I got OCI image attestation working on an Unbound DNS container build. Seeing provenance attached from build system to container image feels like a big milestone.
amf3.github.io/articles/vir...
amf3.github.io/articles/vir...
It's not wrong but it's unexplained.
Here's a demo showing how a manifest is applied to a scratch image so every file exists with intent. No need for a base image or removal of existing packages.
amf3.github.io/articles/vir...
It's not wrong but it's unexplained.
Here's a demo showing how a manifest is applied to a scratch image so every file exists with intent. No need for a base image or removal of existing packages.
amf3.github.io/articles/vir...
What I found interesting wasn't what's in the base image but how much content is present without intent.
Looking forward I'm planning for better declarative builds with a new approach in github.com/amf3/just_en...
What I found interesting wasn't what's in the base image but how much content is present without intent.
Looking forward I'm planning for better declarative builds with a new approach in github.com/amf3/just_en...
Yes it's related to a new article I'm writing.
No it doesn't need to be this way.
Yes it's related to a new article I'm writing.
No it doesn't need to be this way.
zrepl.github.io/changelog.html
zrepl.github.io/changelog.html
amf3.github.io/articles/vir...
#OCI #Containers #DevOps #Hacking #Docker #Podman
amf3.github.io/articles/vir...
#OCI #Containers #DevOps #Hacking #Docker #Podman
coredns.io/manual/setup...
Then why not run unbound? I must be missing something.
coredns.io/manual/setup...
Then why not run unbound? I must be missing something.
holzschu.github.io/a-Shell_iOS/
holzschu.github.io/a-Shell_iOS/
just.systems/man/en/setti...
just.systems/man/en/setti...
I know the API is disabled by default, but enabling it seems to have similar risk as rootless Docker. I never stop being amazed by marketing.
I mean it's not front page content but baby steps right? 😃
I mean it's not front page content but baby steps right? 😃