Skip to content

Daemonless pkg cache Daemonless pkg cache

Description / nameInput element
Container Registry
Container Configuration Root Path
Timezone
Daemonless pkg cache Host Port
Daemonless pkg cache /config Path
Daemonless pkg cache /cache Path

Build Status Last Commit OCI Pulls

Managed FreeBSD pkg caching appliance — proxies pkg.FreeBSD.org to speed up package fetches across image builds and insulate them from upstream rate limits/outages.

Port 80
Registry ghcr.io/daemonless/pkg-cache
Daemonless daemonless/pkg-cache
Source daemonless/pkg-cache
Website daemonless.io/images/pkg-cache

Version Tags

Multi-arch manifests — resolve automatically to the right image for your platform.

Tag Description Best For
latest daemonless Appliance. Managed FreeBSD pkg cache proxy built on nginx-base. Most users — recommended.
Tag Description Best For
latest-amd64 daemonless Appliance. Managed FreeBSD pkg cache proxy built on nginx-base. Most users — recommended.
Tag Description Best For
latest-aarch64 daemonless Appliance. Managed FreeBSD pkg cache proxy built on nginx-base. Most users — recommended.

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions, including the security model for host vs. container privileges.

Deployment

services:
  pkg-cache:
    image: "ghcr.io/daemonless/pkg-cache:latest"
    container_name: pkg-cache
    environment:
      - TZ=UTC  # Timezone for the container
      - PKG_UPSTREAM=pkg.FreeBSD.org  # FreeBSD pkg mirror to proxy, e.g. pkg1.us.freebsd.org or pkg0.eu.freebsd.org. Defaults to the primary pkg.FreeBSD.org.
      - PKG_CACHE_SIZE=50g  # Max on-disk cache size (nginx max_size), e.g. 10g, 100g, 500g. 10g is plenty for light use; keep the /cache volume at least this big.
      - ENABLE_STATS=false  # Set to true to enable the GoAccess real-time stats dashboard on port 7890.
      - SKIP_CHOWN=true  # Skip the startup recursive chown of /config and /cache once ownership is recorded in /config/.chown_done (default true). Set false to force a chown on every start. The marker lives in /config, so /config must be a persistent volume for the skip to take effect across restarts.
      - PKG_LOG_MAX_SIZE=50m  # Size cap for each on-disk log in /config/log (access.log, error.log, goaccess.log), e.g. 10m, 50m, 1g. A log past this is rotated away so /config can't fill; GoAccess keeps full history in its persisted db regardless.
    volumes:
      - "/containers/pkg-cache:/config"
      - "/containers/pkg-cache/cache:/cache"
    ports:
      - "80:80"
      - "7890:7890"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

podman run -d --name pkg-cache \
  -p 80:80 \
  -p 7890:7890 \
  -e TZ=UTC \
  -e PKG_UPSTREAM=pkg.FreeBSD.org \
  -e PKG_CACHE_SIZE=50g \
  -e ENABLE_STATS=false \
  -e SKIP_CHOWN=true \
  -e PKG_LOG_MAX_SIZE=50m \
  -v /containers/pkg-cache:/config \
  -v /containers/pkg-cache/cache:/cache \
  ghcr.io/daemonless/pkg-cache:latest

Save as run.sh, then run sh run.sh.

- name: Deploy pkg-cache
  containers.podman.podman_container:
    name: pkg-cache
    image: "ghcr.io/daemonless/pkg-cache:latest"
    state: started
    restart_policy: always
    env:
      TZ: "UTC"
      PKG_UPSTREAM: "pkg.FreeBSD.org"
      PKG_CACHE_SIZE: "50g"
      ENABLE_STATS: "false"
      SKIP_CHOWN: "true"
      PKG_LOG_MAX_SIZE: "50m"
    ports:
      - "80:80"
      - "7890:7890"
    volumes:
      - "/containers/pkg-cache:/config"
      - "/containers/pkg-cache/cache:/cache"

Save as pkg-cache-deploy.yaml, then run ansible-playbook pkg-cache-deploy.yaml.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

1
2
3
4
5
6
7
8
9
# .env

DIRECTOR_PROJECT=pkg-cache
TZ=UTC
PKG_UPSTREAM=pkg.FreeBSD.org
PKG_CACHE_SIZE=50g
ENABLE_STATS=false
SKIP_CHOWN=true
PKG_LOG_MAX_SIZE=50m
# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  pkg-cache:
    name: pkg_cache
    options:
      - container: 'args:--pull'
      - expose: '80:80 proto:tcp'
      - expose: '7890:7890 proto:tcp'
    oci:
      user: root
      environment:
        - TZ: !ENV '${TZ}'
        - PKG_UPSTREAM: !ENV '${PKG_UPSTREAM}'
        - PKG_CACHE_SIZE: !ENV '${PKG_CACHE_SIZE}'
        - ENABLE_STATS: !ENV '${ENABLE_STATS}'
        - SKIP_CHOWN: !ENV '${SKIP_CHOWN}'
        - PKG_LOG_MAX_SIZE: !ENV '${PKG_LOG_MAX_SIZE}'
    volumes:
      - PKG_CACHE_CONFIG_PATH: /config
      - PKG_CACHE_CACHE_PATH: /cache
volumes:
  PKG_CACHE_CONFIG_PATH:
    device: '/containers/pkg-cache'
  PKG_CACHE_CACHE_PATH:
    device: '/containers/pkg-cache/cache'
1
2
3
4
5
6
7
# Makejail

ARG tag=latest

OPTION container=boot
OPTION overwrite=force
OPTION from=ghcr.io/daemonless/pkg-cache:${tag}

Save the files above, then run appjail-director up.

appjail oci run -Pd \
  -o overwrite=force \
  -o container="args:--pull" \
  -o virtualnet=":<random> default" \
  -o nat \
  -o expose="80:80 proto:tcp" \
  -o expose="7890:7890 proto:tcp" \
  -e TZ=UTC \
  -e PKG_UPSTREAM=pkg.FreeBSD.org \
  -e PKG_CACHE_SIZE=50g \
  -e ENABLE_STATS=false \
  -e SKIP_CHOWN=true \
  -e PKG_LOG_MAX_SIZE=50m \
  -o fstab="/containers/pkg-cache /config <pseudofs>" \
  -o fstab="/containers/pkg-cache/cache /cache <pseudofs>" \
  ghcr.io/daemonless/pkg-cache:latest pkg-cache

Save the files above, then run sh run.sh.

Experimental

Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.

services:
  pkg-cache:
    name: pkg-cache
    image: "ghcr.io/daemonless/pkg-cache:latest"
    network:
      - mode: host
    environment:
      - TZ=UTC
      - PKG_UPSTREAM=pkg.FreeBSD.org
      - PKG_CACHE_SIZE=50g
      - ENABLE_STATS=false
      - SKIP_CHOWN=true
      - PKG_LOG_MAX_SIZE=50m
    volumes:
      - "/containers/pkg-cache:/config"
      - "/containers/pkg-cache/cache:/cache"

Save as bastille-compose.yml, then run bastille up.

bastille create -O \
  --env TZ=UTC \
  --env PKG_UPSTREAM=pkg.FreeBSD.org \
  --env PKG_CACHE_SIZE=50g \
  --env ENABLE_STATS=false \
  --env SKIP_CHOWN=true \
  --env PKG_LOG_MAX_SIZE=50m \
  --volume /containers/pkg-cache /config \
  --volume /containers/pkg-cache/cache /cache \
  pkg-cache ghcr.io/daemonless/pkg-cache:latest inherit

Access at: http://localhost:80

Interactive Configuration

Parameters

Environment Variables

Variable Default Description
TZ UTC Timezone for the container
PKG_UPSTREAM pkg.FreeBSD.org FreeBSD pkg mirror to proxy, e.g. pkg1.us.freebsd.org or pkg0.eu.freebsd.org. Defaults to the primary pkg.FreeBSD.org.
PKG_CACHE_SIZE 50g Max on-disk cache size (nginx max_size), e.g. 10g, 100g, 500g. 10g is plenty for light use; keep the /cache volume at least this big.
ENABLE_STATS false Set to true to enable the GoAccess real-time stats dashboard on port 7890.
SKIP_CHOWN true Skip the startup recursive chown of /config and /cache once ownership is recorded in /config/.chown_done (default true). Set false to force a chown on every start. The marker lives in /config, so /config must be a persistent volume for the skip to take effect across restarts.
PKG_LOG_MAX_SIZE 50m Size cap for each on-disk log in /config/log (access.log, error.log, goaccess.log), e.g. 10m, 50m, 1g. A log past this is rotated away so /config can't fill; GoAccess keeps full history in its persisted db regardless.

Volumes

Path Description
/config Logs, generated stats storage (log/, stats/), and the startup ownership marker (.chown_done). Mount as a persistent volume so the chown is skipped on later starts.
/cache Package cache storage (proxy_cache). Size to match max_size in nginx.conf (default 50G; 10G is fine for light use).

Ports

Port Protocol Description
80 TCP HTTP — pkg clients point their FreeBSD.conf url here
7890 TCP GoAccess stats dashboard (HTML) — enabled via ENABLE_STATS=true

How it works

Package files (*.pkg) are cached for 365 days — their filenames are versioned and immutable, so a HIT is always safe. Catalog metadata (meta.conf, packagesite.*, data.*) is cached for 1 minute instead, so pkg keeps resolving the latest updates without serving stale catalogs.

Pointing clients at the cache

On a build host (or any FreeBSD box), drop in /usr/local/etc/pkg/repos/FreeBSD.conf:

1
2
3
4
5
6
7
FreeBSD: {
  url: "http://<cache-host>/${ABI}/quarterly",
  mirror_type: "none",
  signature_type: "fingerprints",
  fingerprints: "/usr/share/keys/pkg",
  enabled: yes
}

Use plain http://, not pkg+http:// — pkg on FreeBSD 15 rejects the pkg+ scheme unless mirror_type is srv.

Then pkg update fetches through the cache — first pull is a MISS, everything after is a HIT, and package signatures still verify end-to-end.

pkg audit can use the cache too — the appliance proxies the FreeBSD vulnerability database at /vuxml/:

echo 'VULNXML_SITE = "http://<cache-host>/vuxml/vuln.xml.xz";' >> /usr/local/etc/pkg.conf

No nginx config is required; the appliance renders its managed config at startup from environment variables. Size the /cache volume to at least PKG_CACHE_SIZE (default 50G — 10G is plenty for a handful of hosts/images, bump it up if you're caching a large fleet).

Implementation Details

  • Architectures: amd64, aarch64
  • User: bsd (UID/GID set via PUID/PGID). Defaults to 1000:1000.
  • Base: Built on ghcr.io/daemonless/base (FreeBSD 15.1).

Need help? Join our Discord community.