Today, @liberaforms@fosstodon.org released a new version including our work on its Dockerfile.
As explained on the project blog:
"The Dockerfile has been improved in many ways, but most notably, it now uses a multi-stage build. As a result, the final image now only includes the runtime dependencies, and not the development ones any more. This led to a significant size reduction of ~43%! It also helps reduce the attack surface as development tools that can be used to craft exploits, such as gcc, are now absent from the final image."
https://blog.liberaforms.org/2025/09/17/version-450/
This is a first step of a global enhancement regarding the containerisation of LiberaForms. Our next objective is to remove the use of the root account for running the service.
#OpenSource #FOSS #Forms #WebForms #Web #WebApp #Security #OCI #Docker #Container #ContainerImages
#oci
3 posts · Last used 13d
I just managed to create a pipeline and a client for storing DDIs inside of an OCI registry! Now you can do things similar to Universal Blue but with systemd-sysupdate instead and all the benefits that come from it! I'll publish more things and maybe a blog post about how to use it later! Note: This is heavily WIP, but it seems to be working!
https://github.com/tulilirockz/pompona
#systemd #bootc #oci #zirconium #linux #foss #sysupdate
New blog post: Speeding Up Forgejo CI with a Custom OCI Image
My blog's pipeline spent more time installing dependencies than actually building the site. Two commits and one Containerfile later, that step is gone entirely.
Bonus: Forgejo ships with a built-in OCI container registry, so the whole thing is self-contained on a single instance. No Docker Hub, no external registry.
https://blog.hofstede.it/speeding-up-forgejo-ci-with-a-custom-oci-image/
#Forgejo #CICD #Containers #DevOps #SelfHosting #OCI #linux
You've seen all posts
