<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Dbuild on Michael Johnson</title>
    <link>https://ahze.net/tags/dbuild/</link>
    <description>Recent content in Dbuild on Michael Johnson</description>
    <image>
      <title>Michael Johnson</title>
      <url>https://ahze.net/images/profile.jpg</url>
      <link>https://ahze.net/images/profile.jpg</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 01 Aug 2026 15:00:00 -0400</lastBuildDate>
    <atom:link href="https://ahze.net/tags/dbuild/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Transparent Supply Chains: First-Class SBOMs in Daemonless &amp; dbuild</title>
      <link>https://ahze.net/posts/transparent-sboms-with-dbuild/</link>
      <pubDate>Sat, 01 Aug 2026 15:00:00 -0400</pubDate>
      <guid>https://ahze.net/posts/transparent-sboms-with-dbuild/</guid>
      <description>&lt;p&gt;Supply chain security in modern container ecosystems is often treated as a post-build afterthought: a secondary scanner runs against a finished image and tries to infer what packages are inside.&lt;/p&gt;
&lt;p&gt;When building native FreeBSD OCI images at &lt;a href=&#34;https://daemonless.io&#34;&gt;Daemonless&lt;/a&gt;, we decided to make supply chain transparency a first-class citizen from day one. With recent updates to our custom build system (&lt;a href=&#34;https://github.com/daemonless/dbuild&#34;&gt;&lt;code&gt;dbuild&lt;/code&gt;&lt;/a&gt;), every container image generated across our entire fleet now produces multi-format &lt;strong&gt;Software Bill of Materials (SBOM)&lt;/strong&gt; artifacts directly at build time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Speeding Up FreeBSD Hosts &amp; Container Builds with a Local pkg Cache</title>
      <link>https://ahze.net/posts/caching-freebsd-packages/</link>
      <pubDate>Wed, 01 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://ahze.net/posts/caching-freebsd-packages/</guid>
      <description>&lt;p&gt;When you run FreeBSD in a homelab across multiple servers, VNET jails, or VMs, routine maintenance quickly reveals a hidden inefficiency. Every time you provision a new jail or update your fleet, each instance independently connects to public &lt;code&gt;pkg.FreeBSD.org&lt;/code&gt; mirrors to download identical packages. If you have a dozen jails running services that need Python, SQLite, or FFmpeg, your WAN connection downloads the exact same binary archives a dozen times.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
