Configuration

Bastille is configured using a config file located at /usr/local/etc/bastille/bastille.conf.

When first installing bastille, you should run bastille setup, which ask if you want to copy the sample file from /usr/local/etc/bastille/bastille.conf.sample to /usr/local/etc/bastille/bastille.conf. After choosing “yes” Bastille will also attemplt to configure storage settings. If you use ZFS, Bastille will configure it for you. If you have multiple pools, you will be asked which one you want to use for Bastille. If not, the default of UFS will be chosen. See ZFS Support.

Bastill will also configure the pf firewall for you by copying a default pf.conf file to /etc/pf.conf for you, but only if it doesn’t exist yet. Once you have reviewed it, start pf with service pf start.

This is the default bastille.conf.sample file.

#####################
## [ BastilleBSD ] ##
#####################

## Default paths
bastille_prefix="/usr/local/bastille"                                 ## default: "/usr/local/bastille"
bastille_backupsdir="${bastille_prefix}/backups"                      ## default: "${bastille_prefix}/backups"
bastille_cachedir="${bastille_prefix}/cache"                          ## default: "${bastille_prefix}/cache"
bastille_jailsdir="${bastille_prefix}/jails"                          ## default: "${bastille_prefix}/jails"
bastille_releasesdir="${bastille_prefix}/releases"                    ## default: "${bastille_prefix}/releases"
bastille_templatesdir="${bastille_prefix}/templates"                  ## default: "${bastille_prefix}/templates"
bastille_logsdir="/var/log/bastille"                                  ## default: "/var/log/bastille"

## PF firewall configuration path
bastille_pf_conf="/etc/pf.conf"                                       ## default: "/etc/pf.conf"

## Bastille commands directory (assumed by bastille pkg)
bastille_sharedir="/usr/local/share/bastille"                         ## default: "/usr/local/share/bastille"

## Bootstrap archives, which components of the OS to install.
## base  - The base OS, kernel + userland
## lib32 - Libraries for compatibility with 32 bit binaries
## ports - The FreeBSD ports (3rd party applications) tree
## src   - The source code to the kernel + userland
## test  - The FreeBSD test suite
## Whitespace-separated list:
## bastille_bootstrap_archives="base lib32 ports src test"
bastille_bootstrap_archives="base"                                    ## default: "base"

## Pkgbase package sets
## Any set with [-dbg] can be installed with debugging
## symbols by adding '-dbg' to the package set
## base[-dbg]          - Base system
## base-jail[-dbg]     - Base system for jails
## devel[-dbg]         - Development tools
## kernels[-dbg]       - Base system kernels
## lib32[-dbg]         - 32-bit compatability libraries
## minimal[-dbg]       - Basic multi-user system
## minimal-jail[-dbg]  - Basic multi-user jail system
## optional[-dbg]      - Optional base system software
## optional-jail[-dbg] - Optional base system software for jails
## src                 - System source code
## tests               - System test suite
## Whitespace-separated list:
## bastille_pkgbase_packages="base-jail lib32-dbg src"
bastille_pkgbase_packages="base-jail"                                 ## default: "base-jail"

## Default timezone
bastille_tzdata=""                                                    ## default: empty to use host's time zone

## Default jail resolv.conf
bastille_resolv_conf="/etc/resolv.conf"                               ## default: "/etc/resolv.conf"

## Bootstrap URLs
bastille_url_freebsd="http://ftp.freebsd.org/pub/FreeBSD/releases/"                  ## default: "http://ftp.freebsd.org/pub/FreeBSD/releases/"
bastille_url_hardenedbsd="https://installers.hardenedbsd.org/pub/"                   ## default: "https://installer.hardenedbsd.org/pub/HardenedBSD/releases/"
bastille_url_midnightbsd="https://www.midnightbsd.org/ftp/MidnightBSD/releases/"     ## default: "https://www.midnightbsd.org/pub/MidnightBSD/releases/"

## ZFS options
bastille_zfs_enable="NO"                                              ## default: "NO"
bastille_zfs_zpool=""                                                 ## default: ""
bastille_zfs_prefix="bastille"                                        ## default: "bastille"
bastille_zfs_options="-o compress=on -o atime=off"                    ## default: "-o compress=on -o atime=off"

## Export/Import options
bastille_compress_xz_options="-0 -v"                                  ## default "-0 -v"
bastille_decompress_xz_options="-c -d -v"                             ## default "-c -d -v"
bastille_compress_gz_options="-1 -v"                                  ## default "-1 -v"
bastille_decompress_gz_options="-k -d -c -v"                          ## default "-k -d -c -v"
bastille_compress_zst_options="-3 -v"                                 ## default "-3 -v"
bastille_decompress_zst_options="-k -d -c -v"                         ## default "-k -d -c -v"
bastille_export_options=""                                            ## default "" predefined export options, e.g. "--live --gz"

## Networking
bastille_network_vnet_type="if_bridge"                                ## default: "if_bridge"
bastille_network_loopback="bastille0"                                 ## default: "bastille0"
bastille_network_pf_ext_if="ext_if"                                   ## default: "ext_if"
bastille_network_pf_table="jails"                                     ## default: "jails"
bastille_network_shared=""                                            ## default: ""
bastille_network_gateway=""                                           ## default: ""
bastille_network_gateway6=""                                          ## default: ""

## Default Templates
bastille_template_base="default/base"                                 ## default: "default/base"
bastille_template_empty=""                                            ## default: "default/empty"
bastille_template_thick="default/thick"                               ## default: "default/thick"
bastille_template_clone="default/clone"                               ## default: "default/clone"
bastille_template_thin="default/thin"                                 ## default: "default/thin"
bastille_template_vnet="default/vnet"                                 ## default: "default/vnet"
bastille_template_vlan="default/vlan"                                 ## default: "default/vlan"

## Monitoring
bastille_monitor_cron_path="/usr/local/etc/cron.d/bastille-monitor"                           ## default: "/usr/local/etc/cron.d/bastille-monitor"
bastille_monitor_cron="*/5 * * * * root /usr/local/bin/bastille monitor ALL >/dev/null 2>&1"  ## default: "*/5 * * * * root /usr/local/bin/bastille monitor ALL >/dev/null 2>&1"
bastille_monitor_logfile="${bastille_logsdir}/monitor.log"                                    ## default: "${bastille_logsdir}/monitor.log"
bastille_monitor_healthchecks=""                                                              ## default: ""

Notes

The options here are fairly self-explanitory, but there are some things to note.

  • Bastille will mount the dataset it creates at bastille_prefix which defaults to /usr/local/bastille. So if you want to navigate to your jails, you will use the bastille_prefix as the location as this is where they will be mounted.