<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>crod.me</title><link>https://crod.me/</link><description>Recent content in Home on crod.me</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>contact@crod.org (Chris Rodríguez Medina)</managingEditor><webMaster>contact@crod.org (Chris Rodríguez Medina)</webMaster><lastBuildDate>Sat, 13 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://crod.me/index.xml" rel="self" type="application/rss+xml"/><item><title>Money I can hold</title><link>https://crod.me/posts/money-i-can-hold/</link><pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate><author>contact@crod.org (Chris Rodríguez Medina)</author><guid>https://crod.me/posts/money-i-can-hold/</guid><description>&lt;h2 id="i-rent"&gt;I rent&lt;/h2&gt;
&lt;p&gt;I rent the place I live in. I pay every month for a roof that will never have my name on it, and at the end of it I will own exactly nothing. That is the normal thing, almost everyone I know does it, and there is nothing wrong with it. Plenty of people rent because there is no other option, myself included right now, and that is fine, it is just not where you want to end up. And the normal advice is to flip it around as fast as you can. Stop renting, start owning, and then own enough that other people pay rent to you. That is supposed to be the whole game.&lt;/p&gt;
&lt;p&gt;I have thought about money for years, read a lot of it, argued with most of it, and I keep snagging on that last step.&lt;/p&gt;
&lt;p&gt;So this is not a how to get rich post, and it is not advice. It is closer to a confession of how I think money is supposed to work, and where I have decided to stop. For me money turns out to be a moral question before it is a math question, which is the opposite of how it usually gets written about. So I want to start with the ethics and the philosophy, and only then get to what I actually own and why. You can skip around. The headings are there for that.&lt;/p&gt;
&lt;h2 id="durability-over-yield"&gt;Durability over yield&lt;/h2&gt;
&lt;h3 id="still-standing-in-2055"&gt;Still standing in 2055&lt;/h3&gt;
&lt;p&gt;Here is the whole philosophy in one line. I do not try to make the most money. I try to be the hardest to knock over.&lt;/p&gt;
&lt;p&gt;Most money writing optimizes for the biggest number per year. Best return, highest yield, beat the market. I do not care about that, or I care about it last. The question I actually ask is whether I am still standing in 2055, after whatever the next thirty years decide to throw at me. Up twenty two percent last year means nothing if the thing that produced it blows up in the one year I needed it to hold. Durability beats yield. I would rather have the boring thing that survives than the brilliant thing that might not.&lt;/p&gt;
&lt;h3 id="the-point-of-money-is-to-need-less-of-it"&gt;The point of money is to need less of it&lt;/h3&gt;
&lt;p&gt;Luke Smith has an essay, &lt;a href="https://lukesmith.xyz/articles/why-its-bad-to-have-high-gdp/"&gt;Why It&amp;rsquo;s Bad to Have High GDP&lt;/a&gt;, that quietly rewired how I see this. His point is that the big number everyone chases does not measure how well off you are, it measures how much you have to run through the system just to stay alive. A family that grows its own food and fixes its own things shows up as almost nothing on that chart, because nothing is being bought. A self-sufficient life has a personal GDP of basically zero. So a high number is not a sign of wealth, a lot of the time it is a sign of fragility, of how much you depend on everything outside you continuing to work.&lt;/p&gt;
&lt;p&gt;Turn that around and the goal flips. The point of money, in the end, is to need less of it. That is the other Luke essay, &lt;a href="https://lukesmith.xyz/articles/minimizing-liabilities-is-making-it/"&gt;Minimizing Liabilities Is Making It&lt;/a&gt;, and it is the same move Jacob Lund Fisker makes in &lt;a href="https://www.goodreads.com/book/show/9519944-early-retirement-extreme"&gt;Early Retirement Extreme&lt;/a&gt;, go after your expenses instead of your returns, because your expenses you control and your returns you do not. This is really the other half of &lt;a href="https://crod.me/posts/financial-independence/"&gt;a thing I already wrote&lt;/a&gt; about getting out early.&lt;/p&gt;
&lt;p&gt;So the real goal is not the biggest pile. It is a handful of different things that each survive a different kind of disaster, so that no single bad year takes the whole thing down. There is a fancy word for that, antifragile, but I do not want to lean on it. The plain version is the old one. Do not put all your eggs in one basket, and make sure the baskets do not all break for the same reason.&lt;/p&gt;
&lt;h3 id="two-good-options-and-a-bad-middle"&gt;Two good options, and a bad middle&lt;/h3&gt;
&lt;p&gt;The way I have come to see it, there are only two good places to be with money, with a bad stretch in between. One is to need very little of it. Spend less, rely less on money and more on yourself, on your own skills, on barter, on the people around you. Community is a huge piece of this and it almost never gets mentioned. A person with neighbors who lend tools and trade food and show up when something breaks is wealthy in a way no account balance will ever show. That is the end I am walking toward.&lt;/p&gt;
&lt;p&gt;The other good place is the opposite extreme, having so much money that you genuinely stop thinking about it. Some sharp people aim for exactly that, get rich enough that the question just disappears. I understand the logic and I am not going to pretend it does not work. But something about it sits wrong with me and I have a hard time naming the feeling. When money stops being any kind of constraint, life starts to look a little like a game with the cheat codes turned on, and I do not think people are at their best that way. I would rather earn my way to needing little than buy my way to not caring.&lt;/p&gt;
&lt;p&gt;The bad place is the middle, and it is where almost everyone lives. Enough money to depend on it completely, never enough to be free of it. Running hard just to keep the machine fed. That is the spot to climb out of, in either direction, and I already know which direction I am picking.&lt;/p&gt;
&lt;h3 id="skills-are-the-one-true-wealth"&gt;Skills are the one true wealth&lt;/h3&gt;
&lt;p&gt;This is the thread running under both Fisker and Luke, and it might be the most important thing on this whole page. Skills are an investment, maybe the best one there is. The more genuinely useful you are, the more you are worth, and not in a resume way. When something goes wrong and you do not know how to do anything, all you have is the money you saved and the hope it still buys something. But if you can fix, build, grow, repair, and make, your worth does not vanish when the market does. Money is just worth materialized, a stand-in for things people can actually do. Skills are the thing itself. Aside from family, they are the one form of wealth nobody can inflate away or take from you, and they deserve their own post, which they will get. For now just know they sit underneath everything here.&lt;/p&gt;
&lt;h2 id="the-landlord-i-wont-become"&gt;The landlord I won&amp;rsquo;t become&lt;/h2&gt;
&lt;h3 id="why-it-sticks"&gt;Why it sticks&lt;/h3&gt;
&lt;p&gt;So, back to the renting thing, because this is the part I genuinely have not made peace with.&lt;/p&gt;
&lt;p&gt;The classic move is simple and it works. Buy a house, rent it out, let the tenant&amp;rsquo;s rent pay down your mortgage, and at the end you own a house that somebody else paid for. Do it a few times over a couple of decades. It is one of the most reliable ways ordinary people have ever built real wealth. And I cannot get comfortable being on that side of it.&lt;/p&gt;
&lt;p&gt;Why not. Because I am on the other side of it right now. I know exactly what it feels like to hand over money every month for something that will never be mine. I do not love the idea of being the guy collecting that. I have always felt a little weird about renting a house to someone who would rather own it, when I would rather own mine too. Is it ethics, is it values, is it just a feeling I have not argued myself out of yet? Honestly I do not know which. I am not going to pretend I have it solved.&lt;/p&gt;
&lt;h3 id="two-ways-to-think-about-it"&gt;Two ways to think about it&lt;/h3&gt;
&lt;p&gt;But I do not want to leave it at a feeling, so let me bring in the two people who thought about this much harder than I have, and who happen to disagree with each other.&lt;/p&gt;
&lt;figure class="sideimg" style="float: left; width: 32%; margin: 10px; padding: 6px; box-sizing: border-box;"&gt;
&lt;img src="https://crod.me/images/henry-george.webp" alt="Portrait photograph of Henry George" width="480" height="699" style="width: 100%; height: auto; display: block;"&gt;
&lt;figcaption style="text-align: center; font-size: 0.85em; font-style: italic; margin-top: 4px;"&gt;Henry George, around 1885.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;The first is Henry George, in &lt;a href="https://www.gutenberg.org/files/55308/55308-h/55308-h.htm"&gt;Progress and Poverty&lt;/a&gt;. His argument is that land is a little different from other things you can own, because most of what makes a piece of land valuable is not anything the owner did. A neighborhood, a city, a road, other people showing up and building lives nearby, those are what make the ground worth something, and the owner just collects the rent on it. Push it to the limit, which is George&amp;rsquo;s own example, if one man owned all the land around a town he could charge whatever he liked for the right to live there, and everyone else would simply have to pay. That is not trade. That is a toll.&lt;/p&gt;
&lt;p&gt;The second is the encyclical &lt;a href="https://www.vatican.va/content/leo-xiii/en/encyclicals/documents/hf_l-xiii_enc_15051891_rerum-novarum.html"&gt;Rerum Novarum&lt;/a&gt;, which is the side I was raised closer to. It defends private property, land included, as a real and natural thing. You mix your work and your care into something and it becomes yours, and the people who want to abolish all private ownership tend to wreck the very people they say they are rescuing. But it does not stop there, and the part that sticks with me is the limit it puts on ownership. What you own, you hold as a kind of trust, not a trophy. The earth was given to everyone. The man who has more than he needs owes something to the man who has less, and the poor have a real claim on his conscience.&lt;/p&gt;
&lt;p&gt;Those two genuinely disagree, Leo XIII wrote part of that letter to answer George directly, and I am not going to settle a fight that outlived both of them. But I notice they agree on the one thing I actually need them to agree on. Owning in a way that corners or wrecks other people is wrong, even when it is perfectly legal.&lt;/p&gt;
&lt;h3 id="the-honest-versions"&gt;The honest versions&lt;/h3&gt;
&lt;p&gt;Now, there are honest ways to be a landlord, and I want to be fair about that, because the man who taught me the most about real estate, &lt;a href="https://www.johnschaub.com/"&gt;John Schaub&lt;/a&gt;, is about as far from a slumlord as a person can get.&lt;/p&gt;
&lt;p&gt;His whole method is built to be good to the tenant. Fair rent, repairs actually done, tenants who stay for years because they are treated well, and little touches like a discount for paying on time instead of a penalty for paying late, which is the same money framed as a reward instead of a punishment. The tenant is the point, not a yield to squeeze. If you are going to do it, that is how.&lt;/p&gt;
&lt;p&gt;And there is a version that gets rid of the landlord relationship altogether. You buy the house, then you sell it to the person living in it on long terms, so that they actually own their home and you just hold the note. You become the bank instead of the landlord. They build equity in a place that is theirs, and you still get paid for the capital you put up. If I ever did any of this, that is the only shape I would want.&lt;/p&gt;
&lt;h3 id="probably-no"&gt;Probably no&lt;/h3&gt;
&lt;p&gt;But where I have actually landed is, probably not at all.&lt;/p&gt;
&lt;p&gt;A house I own and live in, some metal in a safe, a piece of land. That is backbone enough. I do not need a tenant to feel secure. And if the last little sliver of security that being a landlord would buy me costs me something I would feel weird about every time I thought about it, then it is too expensive. That is the honest answer. I am close to settled on it. Probably no, and if ever, then only as the bank.&lt;/p&gt;
&lt;h2 id="a-word-on-land"&gt;A word on land&lt;/h2&gt;
&lt;h3 id="they-are-not-making-more-of-it"&gt;They are not making more of it&lt;/h3&gt;
&lt;p&gt;The thing underneath all of that is bigger than houses. It is land itself, and it is enough of its own subject that it is going to get its own post. So here is just the small version.&lt;/p&gt;
&lt;p&gt;They are not making any more of it. And like George said, a lot of what land is worth is worth that because of everyone else, not because of the owner. So when someone owns far more land than they will ever use, and holds it mostly to collect what everybody else&amp;rsquo;s presence makes it worth, something is off to me. Even when it is legal. Even when, if I am honest, I would probably be tempted to do the same in their shoes. I am not a single-taxer, I have not worked out the policy, and a blog paragraph is not going to solve political economy. This is a gut thing I am still thinking through.&lt;/p&gt;
&lt;h3 id="the-village-and-the-hut"&gt;The village and the hut&lt;/h3&gt;
&lt;p&gt;There is an older pattern I keep coming back to, the village. For most of human history nobody carved the world into deeds the way we do now. In a village, or a tribe, the land was simply shared, it was the commons, but each family had its own hut, the home they built and lived in. That always struck me as the natural arrangement, and at first I thought it was the opposite of private property. The longer I sit with it, the more it looks like the two traditions I just described, reconciled. The hut is yours, you built it, you put your work into it, and that is exactly what Rerum Novarum protects. The land underneath is shared, because the land is the thing everyone needs and nobody made, which is exactly George&amp;rsquo;s point. Private home, common ground. Maybe that is not so different from what we have now, or maybe it is the entire difference. I am still turning it over.&lt;/p&gt;
&lt;h3 id="land-in-use"&gt;Land in use&lt;/h3&gt;
&lt;p&gt;What bothers me is land held &lt;em&gt;out&lt;/em&gt; of use. Land in use is a completely different thing.&lt;/p&gt;
&lt;p&gt;If I owned land I was not working, the move that sits fine with me is to rent it to someone who wants to work it. Land farmed by a person who wants to farm it is land doing its job, and renting it to them is the same honest shape as selling the house to the family living in it. The problem was never owning land, or even renting it out. The problem is holding it idle as a toll on the people who would actually use it.&lt;/p&gt;
&lt;p&gt;Now I want to be careful, because &amp;ldquo;use it or it is wasted&amp;rdquo; is too blunt and I do not actually believe it. Some land should sit untouched. Wild land, protected nature, a forest thick with animals and a tangle of life that would be wrecked the moment someone developed it, that is not idle land, that is land doing the most important job there is. Same with a piece somebody is genuinely holding for a real plan they have not gotten to yet. What I am uneasy about is narrower than unused land. It is land hoarded purely as a toll, fenced off from everyone not to protect anything or build anything, just to collect what other people&amp;rsquo;s presence makes it worth. Leaving a stretch of the earth wild on purpose is the opposite of that.&lt;/p&gt;
&lt;p&gt;And the truth is that my real dream, the thing I would do if the money were handled, is not to be a landlord of anything. It is to be self-sufficient on my own ground. Cows, sheep, chickens, a few vegetables, and mostly fruit. I do not farm yet, not really, so I am not going to write like a homesteader when I am not one. That is a post for when I have actually put my hands in the dirt. But that is the direction I am pointed, and you can see how it lines up with everything else here. Land that feeds you has a personal GDP of almost nothing, and depends on almost no one. That is the whole idea, just made of soil instead of money.&lt;/p&gt;
&lt;h2 id="gold-and-silver"&gt;Gold and silver&lt;/h2&gt;
&lt;h3 id="the-oldest-money-there-is"&gt;The oldest money there is&lt;/h3&gt;
&lt;p&gt;Now the part that actually sits in a safe.&lt;/p&gt;
&lt;figure class="sideimg" style="float: right; width: 36%; margin: 10px; padding: 6px; box-sizing: border-box;"&gt;
&lt;img src="https://crod.me/images/morgan-dollar.webp" alt="An 1879 Morgan silver dollar, obverse" width="480" height="480" style="width: 100%; height: auto; display: block;"&gt;
&lt;figcaption style="text-align: center; font-size: 0.85em; font-style: italic; margin-top: 4px;"&gt;An 1879 Morgan silver dollar.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Gold and silver are the most boring money there is, and the oldest. Metal you can hold in your hand has been money for most of human history. Paper promises come and go, governments and their currencies come and go, and the metal just sits there and stays money. Roy Jastram spent an entire book, &lt;a href="https://www.goodreads.com/book/show/3267510-the-golden-constant"&gt;The Golden Constant&lt;/a&gt;, measuring exactly this across four and a half centuries of records. The finding is subtle and worth getting right. Gold is not a reliable short-term inflation hedge, in any given year it can lag badly or run ahead. But over the long run its purchasing power keeps coming back to the same stable average. It is not that gold goes up, it is that gold stays put while everything measured against it wobbles. Somebody put it perfectly once, gold is not a get-rich asset, it is a get-through asset. That is exactly how I hold it. Insurance, not a bet.&lt;/p&gt;
&lt;h3 id="honest-money"&gt;Honest money&lt;/h3&gt;
&lt;p&gt;There is a moral case too, and it is the one that actually moved me. Money you cannot print is honest money. Murray Rothbard lays out the mechanics in &lt;a href="https://mises.org/library/book/what-has-government-done-our-money"&gt;What Has the Government Done to Our Money?&lt;/a&gt;, and Jörg Guido Hülsmann puts the ethics of it plainly in &lt;a href="https://mises.org/library/book/ethics-money-production"&gt;The Ethics of Money Production&lt;/a&gt;, both free to read. The short version is that printing money is not free and it is not neutral. It quietly moves real wealth from the people holding the currency to whoever gets the new money first, before prices catch up. That is not a metaphor and it is not an accident, it is the mechanism. A slow, legal, invisible transfer that nobody votes on. Metal cannot be printed, and that is most of the appeal right there. There is only so much gold and silver in the earth&amp;rsquo;s crust, a finite amount no government and no central bank can conjure more of. The same goes for land, there is exactly as much of it as there has always been. Scarcity you cannot fake is what lets a thing hold value at all. A currency you can create without limit will, given enough time, be worth almost nothing.&lt;/p&gt;
&lt;h3 id="friction-is-a-feature"&gt;Friction is a feature&lt;/h3&gt;
&lt;p&gt;Here is something people treat as a downside that I treat as the opposite. I cannot panic-sell a silver bar in San Juan in two seconds the way I can dump an ETF on my phone in the middle of a bad night. That friction is not a bug. It is the asset working as designed. It keeps me from doing the stupid thing at the bottom. The hardest part of holding anything for thirty years is not selling it in year three when you get scared, and metal you have to physically carry to a dealer makes year three easy.&lt;/p&gt;
&lt;h3 id="silver-the-soft-spot"&gt;Silver, the soft spot&lt;/h3&gt;
&lt;p&gt;I will be honest about one thing. I hold more silver than gold, and part of that is sentiment, not spreadsheet. Silver just has a soft spot in my heart.&lt;/p&gt;
&lt;p&gt;There is a real case under the feeling, though. Silver has an industrial demand floor that gold does not, it was the everyday-transaction money for most of history in a way gold never really was, and you can stack it on a normal budget without ever buying a single piece that costs a paycheck. There is also the gold-silver ratio, how many ounces of silver it takes to buy one ounce of gold. Across the long sweep of history that number has sat far lower than it does today, and when it gets stretched wide, eighty or a hundred to one, it tends to narrow back toward its average eventually. It never closes all the way, and it is not a crystal ball, but it is a rough band, and plenty of people use it to decide which metal to stack, the cheaper one by the ratio. When silver is historically cheap against gold, I lean silver, and the heart and the ratio happen to agree. But I am not going to dress the feeling up as pure analysis. Gold is the senior money and I hold it too. Silver just has my heart, and I figure I am allowed one of those.&lt;/p&gt;
&lt;h2 id="monero"&gt;Monero&lt;/h2&gt;
&lt;h3 id="permanent-storage-not-a-bet"&gt;Permanent storage, not a bet&lt;/h3&gt;
&lt;p&gt;One piece of this is digital, and it is the one most people will read wrong, so let me say it plainly first. I do not treat &lt;a href="https://www.getmonero.org/"&gt;Monero&lt;/a&gt; as an investment. It is permanent storage. A small thing I hold because I might need it one day, not because I think it is going to moon. Even Luke, who is the reason I hold it at all, says straight out that he has no idea whether it moons or crashes, and that the price is not why you hold it. You hold it for what it does, not what its number might do.&lt;/p&gt;
&lt;h3 id="glass-walls"&gt;Glass walls&lt;/h3&gt;
&lt;p&gt;So what does it do. It is the only digital money I know of that does the one thing money is actually supposed to do, which is keep your business your business.&lt;/p&gt;
&lt;p&gt;Here is the part almost nobody realizes about cryptocurrency, and Luke says it best in &lt;a href="https://lukesmith.xyz/articles/monero-maximalism-or-how-bitcoin-is-a-coin/"&gt;Monero Maximalism&lt;/a&gt;. Most of it is the opposite of private. Bitcoin and nearly all the rest run on a public ledger that anyone on earth can read, forever. Every balance, every payment, permanently visible to everybody. That is not privacy. Those are glass walls. And here is the thing, every currency in human history has been private. You do not broadcast your bank balance to the planet when you hand somebody cash, and the dollar and the euro keep that basic decency too. Most crypto just threw it away and called the bug a feature.&lt;/p&gt;
&lt;p&gt;That is also exactly why I will never own Bitcoin. Not the price, not the drama. A ledger the whole world can read was never private money, and that is the design, not a flaw you can patch later. Monero does the bare minimum a money should do, it hides who paid, who got paid, and how much, and it does it by default for everyone. Ring signatures, stealth addresses, hidden amounts. None of it is exotic. It is just money that minds its own business. If you want the whole case laid out better than I can do it here, watch the talk &lt;a href="https://www.youtube.com/watch?v=8quGD9W7B2I"&gt;Monero Means Money&lt;/a&gt;. I keep my stack small, I keep it myself and never on someone else&amp;rsquo;s exchange, and I hold it forever.&lt;/p&gt;
&lt;h2 id="the-permanent-portfolio"&gt;The permanent portfolio&lt;/h2&gt;
&lt;h3 id="the-boring-liquid-layer"&gt;The boring liquid layer&lt;/h3&gt;
&lt;p&gt;Everything up to here is the backbone, the stuff I hold forever and mostly do not touch. Then there is the part that looks like an ordinary portfolio, and I think about it the least, on purpose.&lt;/p&gt;
&lt;p&gt;It is built on &lt;a href="https://www.harrybrowne.org/"&gt;Harry Browne&lt;/a&gt;&amp;rsquo;s idea, the Permanent Portfolio, and it is worth spelling out instead of leaving you to guess. The classic version is four equal pieces, 25% each, and each piece is there for a different kind of economic weather. Stocks for the good years when the economy is growing. Long-term government bonds, the 25 or 30 year kind, for deflation and falling interest rates. Gold for inflation and currency trouble. And cash, meaning short-term Treasury bills, for the lean recession years when everything else is down. Whatever the world does, one of the four is built to do well while another takes the hit, and they hold each other up.&lt;/p&gt;
&lt;p&gt;Owning them is simple. A single broad stock index fund is the first quarter, long Treasuries or a fund that holds them are the second, physical gold or a gold ETF the third, and Treasury bills or a Treasury money market the fourth. You almost never sell. The only time you touch it is to rebalance, and Browne&amp;rsquo;s rule for that is the 15/35 band. You leave the whole thing alone until one of the four grows past 35% of the total or shrinks below 15%, and only then do you sell a little of whatever got too big and top up whatever got too small, back to roughly a quarter each. After that you go back to ignoring it, which in practice might be once every few years. In my own case the gold quarter already lives in the backbone above, the metal I hold in hand, so my own liquid version just runs the other three. &lt;a href="https://www.goodreads.com/book/show/13838783-the-permanent-portfolio"&gt;Craig Rowland&lt;/a&gt; wrote the practical book on running one well.&lt;/p&gt;
&lt;h3 id="boring-and-it-holds-up"&gt;Boring and it holds up&lt;/h3&gt;
&lt;p&gt;I do not think of this layer as the wealth. It is structured savings. It is my bank account with a better haircut. The metal and the land and the house are the wealth. This is the liquid part that lets me not touch any of that when life happens.&lt;/p&gt;
&lt;p&gt;And the reason it is built this way is not to win. It is to never blow up, so that you can actually hold it through a 2008 or a 2020 or a 2022 without panic-selling at the very bottom like most people do. Boring, and it holds up, which is really the whole point. The day you catch yourself checking it every morning, it has stopped doing its job, and so have you.&lt;/p&gt;
&lt;h2 id="buy-when-you-can"&gt;Buy when you can&lt;/h2&gt;
&lt;p&gt;One habit runs through every single piece of this, the gold and the silver, the land, all of it. Dollar cost averaging. You buy a little at a time, on a schedule, no matter what the price is doing.&lt;/p&gt;
&lt;p&gt;The instinct is always the same. Gold and silver are so expensive right now, I should wait for a dip. But if you live by that instinct you will never actually do anything, or you will spend your life waiting for a bubble to pop on command, which is just gambling with extra steps. Nobody knows the future. Nobody. If you buy and it drops the next week, oh well, boohoo, you keep buying, and your average comes out fine across the years that actually matter.&lt;/p&gt;
&lt;p&gt;I am not saying this to turn it into a spreadsheet or some investing-blog tactic. It is simpler and more important than that. You are alive right now, in this moment, and the only way any of this works is if you actually start. Buy when you can. Do not wait for the perfect time, and do not wait for anyone, me included, to tell you the moment is right. There is no perfect moment. There is just the habit, repeated, while you get on with your life.&lt;/p&gt;
&lt;h2 id="what-ties-it-together"&gt;What ties it together&lt;/h2&gt;
&lt;p&gt;Look at the whole thing and it is one idea, not seven. Durability over yield, run through everything I own. Metal that just sits there and stays money. A house I own and do not rent out. A currency I hold in case the world ever needs it. A boring middle I try hard not to think about. A dream of land that feeds me. Each one survives a different kind of bad day, and not one of them depends on me being right about next year.&lt;/p&gt;
&lt;p&gt;And under all of it there is the other thread, the one I opened with. I will not build the pile in a way I would have to look away from. Being secure is just not worth becoming the thing I would not want done to me. It is the same line in money as everywhere else, you can &lt;a href="https://crod.me/posts/do-what-you-want/"&gt;do what you want&lt;/a&gt; right up until it would wreck somebody else, and then you stop.&lt;/p&gt;
&lt;p&gt;And honestly, you can ignore every word of this. You can skip the metal and the Monero and all the rest, find work you genuinely love that AI cannot swallow, farming, electrical, construction, a real craft, own the home you live in, and just be happy. That might be the whole secret, and it would make this entire post unnecessary. I would not even be mad.&lt;/p&gt;
&lt;p&gt;I rent right now. Maybe I always will feel a little weird about it. But I would rather be the guy who still feels weird about it than the guy who stopped asking the question.&lt;/p&gt;</description></item><item><title>Do What You Want</title><link>https://crod.me/posts/do-what-you-want/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><author>contact@crod.org (Chris Rodríguez Medina)</author><guid>https://crod.me/posts/do-what-you-want/</guid><description>&lt;p&gt;The strongest people do what they want, when they want. Strength is when the choice starts in you and you carry it out. It came from you and you did it. That is the whole of it, and none of it depends on whether the choice was any good.&lt;/p&gt;
&lt;p&gt;I can hear the objection already, because it is the obvious one. A serial killer does what he wants. So is he strong? In this narrow sense, yes. And no, that does not make it right, everyone already knows that. But watch what just happened in your head. You heard strong and you reached for good, like they were the same word. They are not. Strength is one question. Whether the choice was any good is a different question. Two different questions, two different answers. Most people smash the two together so they never have to look at either one straight. And honestly, most killers are not even strong by this test. A compulsion is not a want, it is a leash. But the rare one whose want is truly his own is strong and evil at the same time, and that is exactly why the two questions have to stay separate.&lt;/p&gt;
&lt;p&gt;Take something small. I know how to eat healthy. Everyone tells me to, and they are right, I should. But some days I want the burger, so I go and eat the burger. The strength is not in the burger, the burger is bad for me. The strength is that I wanted something and went and got it. Whether it was good for me is a separate question with its own answer, and that answer is no.&lt;/p&gt;
&lt;p&gt;Now something bigger. I spent the better part of a year teaching myself Latin. A dead language, no job at the end of it, and everyone will tell you the time was better spent on almost anything else. I did it anyway. Was it the smart use of the hours? Probably not. But it was mine. That is the line. Not I was right. Just it is mine. Those are two different claims, and only one of them is about strength.&lt;/p&gt;
&lt;p&gt;Here is where it gets harder, and this is the part almost everyone skips. Before you can do what you want, you have to actually want it. Your own want, not the one installed in you. And most of what we call wanting is copied. You got it off a screen, a friend, an ad, some hole in you an ad found first. Even my burger. If I only wanted it because the commercial taught me to, then eating it was obedience, not strength. Defying your doctor to obey an advertiser is not freedom. It is changing who owns you. Contrarianism is the same thing. You are still letting the crowd decide, you have just agreed to always do the opposite. The rarest strength is not doing what you want. It is having wants that are actually yours. Most people are not caging some wild true self. They never had their own wants to begin with. There is nothing in there to set free.&lt;/p&gt;
&lt;p&gt;So what stops this from being a permission slip to hurt people? Not society. Society&amp;rsquo;s rules are negotiable, and half of them exist to keep you easy to manage. The limit comes from something older. Human nature. And human nature, under everything, is to love and to be in communion with other people. So do what your soul wants, and stop at the line where it would wreck or hurt someone else. That line is not made of laws. It is made of the fact that the other guy is a person too. You can argue with society&amp;rsquo;s rules. Not that one.&lt;/p&gt;
&lt;p&gt;The strange thing is that the same theft happens to knowing, not just to wanting. We get trained out of trusting ourselves there too. The lesson goes like this. Science is always right. Your body is stupid. Do not listen to it. Defer to the study, the expert, the institution, and treat whatever you actually feel as noise. So I am in the gym and my body is screaming that something is wrong, stop, and I push through the pain anyway, because pushing through is what you are supposed to do. For what? I tore something to hit a number a program handed me. For what?&lt;/p&gt;
&lt;p&gt;I am not against science, that is not the claim. The claim is that nobody else is in there with you. The study is an average of strangers, and you are not an average. When the paper and your own body disagree, the paper is not automatically right, it only sounds more official.&lt;/p&gt;
&lt;p&gt;None of this is a license. Trusting yourself with no brakes is its own trap. You can follow your own signal right off a cliff, ignore everyone who warned you, and call it freedom the whole way down. The signal is not always right. That is what the one line is for, the one about not wrecking other people. You still have to use it.&lt;/p&gt;
&lt;p&gt;So, who this is for. This is medicine, and medicine is for the sick. Almost everyone I know is domesticated. Every choice pre approved, every belief footnoted, every want secondhand. If that is you, and it probably is, this is for you. But if you are already feral, if you ignore every signal but your own, if you cannot remember the last time you doubted yourself, this is not your post. You need the opposite one. You need to be told to listen to somebody else for once. Figure out which one you are first.&lt;/p&gt;
&lt;p&gt;Strength was never goodness. It never was. It is the plain fact that the choice came from you and you did it, not from the crowd, the screen, or the people who find you convenient when you obey. Get your own wants back first. Then steer by what you are, a person made to love and not to wreck. The strongest people do what they want, when they want.&lt;/p&gt;</description></item><item><title>Arriving with boots on the ground</title><link>https://crod.me/posts/arrival/</link><pubDate>Sun, 31 May 2026 00:00:00 +0000</pubDate><author>contact@crod.org (Chris Rodríguez Medina)</author><guid>https://crod.me/posts/arrival/</guid><description>&lt;p&gt;I was driving when it happened.&lt;/p&gt;
&lt;p&gt;I had asked what &lt;em&gt;Arrival&lt;/em&gt; was really about, and a voice was reading the answer back to me through the car speakers. I wasn&amp;rsquo;t expecting much, it was just an ordinary drive.&lt;/p&gt;
&lt;p&gt;But as the voice got to the end, I felt my eyes welling up. And I was smiling heavily at the same time. I guess I didn&amp;rsquo;t choose either one.&lt;/p&gt;
&lt;p&gt;The movie is about a woman who gets to see her whole life before she lives it. She sees that she is going to have a daughter, she sees all the love that comes with her, and she sees that she is going to lose her too. She knows the ending, and she knows the pain that comes with it. Yet she chooses it anyway.&lt;/p&gt;
&lt;p&gt;That is the question the movie left me with. If you knew exactly how your life was going to go, all of it, the good and the loss waiting at the end, would you still choose it?&lt;/p&gt;
&lt;p&gt;I would choose it because I know there would be true love in that life, that is the part that most matters to me. Even the losing part is beautiful in its own way. To know that love reached an ending but you lived and experienced sharing it is the part that hits me. Preparing for pain never really goes as you&amp;rsquo;d expect. You can&amp;rsquo;t know how much something hurts until it does. So we live through it and know that so many countless others go through hard things and come out the other side prevailing. Or not&amp;hellip;&lt;/p&gt;
&lt;p&gt;What this movie really did was make me appreciate the beauty in life. I&amp;rsquo;m sure many of us have been humbled before. But it almost feels defensive, as if you are fighting against someone, when honestly we just have to appreciate how fortunate we are to be living. To have lived and experienced love is such a powerful thing. To know you are not alone, that there are people out there like you, that we breathe and see and live similar things. Isn&amp;rsquo;t that beautiful. I can&amp;rsquo;t help but call life nothing short of that. A gift even.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m not trying to place everyone as equal. Some suffer more misfortune than others, some very badly. But the fact that I&amp;rsquo;m writing this on my own computer, in my own home, in the terminal, with a roof over my head, food, time, and a nice place to sleep should be enough to make me feel at peace. How many do not have this? How many experience love and humanity scarcely? To love and to be loved, and not just people, but plants, nature, water, air, whatever, to be in this life is to be loved for all it has to give. To feel pain, suffering, sorrow, but also happiness, understanding, communion. They go hand in hand. It is all what we call life. And everything is beautiful, even in its own messed up way.&lt;/p&gt;
&lt;p&gt;Whatever you believe, or even if you believe in nothing at all, I think the message is the same. I keep coming back to the Christian iconography, to the absolute form of love given to us by Jesus Christ. It was so profound to understand, even if minutely, that someone sacrificed himself for us. There are few words I have for an action like that. Beautiful falls short of how loving it is.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s what it comes back to. Love. It&amp;rsquo;s all about love.&lt;/p&gt;</description></item><item><title>Getting out early</title><link>https://crod.me/posts/financial-independence/</link><pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate><author>contact@crod.org (Chris Rodríguez Medina)</author><guid>https://crod.me/posts/financial-independence/</guid><description>&lt;p&gt;The normal plan goes something like this. You study for years, then you work for decades, and then maybe, if you saved enough and the markets behaved, you get to stop at 65. The whole way through, you consume. A newer car every few years, a house that costs ten times what you make, subscriptions you forgot you signed up for. The reward for going along with it is that you get to quit at the very end.&lt;/p&gt;
&lt;p&gt;I think that is a bad deal. I am trying to get out of it.&lt;/p&gt;
&lt;p&gt;The first problem is that people confuse income with wealth. A big income with big spending leaves you with nothing. The thing that actually matters is the gap between what you make and what you spend, your savings rate. Jacob Lund Fisker worked this out at &lt;a href="https://earlyretirementextreme.com/"&gt;Early Retirement Extreme&lt;/a&gt;. If you save around 75% of what you make, you are financially independent in about seven years, and it does not really matter how much you earn. Someone making 50k and saving most of it gets there as fast as someone making 200k and saving most of it. Most people save 5 or 10%, which is another way of saying they work forever.&lt;/p&gt;
&lt;p&gt;The second problem is that we act like time is unlimited. You only get your youth once. The years you spend grinding in your 20s are not a loan you pay back at 65, they are just gone. I am not saying don&amp;rsquo;t work hard. I am saying think hard about who you are working hard for, and how much of your own life you are putting off while you do it.&lt;/p&gt;
&lt;p&gt;And the third thing is that consumption is the real trap, not income. The fix is almost never to earn more. It is to spend less, which you can start doing today, and which is completely in your control. That is harder than it sounds, because spending is normal and pushed on you constantly, and being frugal gets read as depriving yourself. It is not. It is freedom. It is having options.&lt;/p&gt;
&lt;p&gt;So what am I doing about it? I am trying to build income that does not depend on my hours, keep my expenses low enough that it is actually enough, and do both early enough that time is on my side. I do not have it all figured out. But the direction is clear to me.&lt;/p&gt;
&lt;p&gt;I also do not want to pretend the answer is to grind now and live later. That is its own trap. If you put off every good thing until some spreadsheet says you are free, you get to that freedom worn out, with nothing left to enjoy it with. The point was never to suffer now for a payout later. It is to work hard and actually live, at the same time, in amounts you can keep up. Both halves matter. Skipping either one is a way to lose.&lt;/p&gt;
&lt;p&gt;A quick word on spending, because I am not against it. Money put into a good tool that lasts is not really consumption, it is closer to an investment. A laptop you keep for ten years, a knife that holds its edge, a server that just runs. Those pay you back over time. Same with skills. The hours you spend learning to fix your own car, write your own code, run your own systems, those compound, and unlike most things you own, a skill cannot be taken from you. So I do not feel bad about spending real money on the right computer or the right book. The bad spend is the subscription you forgot about and the upgrade that is worth less the day after you buy it.&lt;/p&gt;
&lt;p&gt;Here is the hard part though. This does not scale, and it never can. Somebody has to grow the food, drive the trucks, run the wires, fix the water, build the houses. The economy that pays for my freedom runs on people who do not get to opt out when I do. If everyone quit tomorrow, the lights go out within the week. That is not a reason to feel guilty about it, but it is a reason to stop pretending this is some universal escape. It is not. For the few who can actually get there, the real question is not how to get out. It is what you do with the freedom once you have it.&lt;/p&gt;
&lt;p&gt;And the answer is not to lounge harder. The answer is to use it. Build things that outlast you. Teach what you learned. Help the people around you who never had the same options, your family, your neighbors, the kid who wants to learn what you know. Buy your time back and then spend it on something that matters. If financial independence is just a fancier way to do nothing, then the whole thing was a waste.&lt;/p&gt;</description></item><item><title>Using the tool without becoming the tool</title><link>https://crod.me/posts/suckless-ai/</link><pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate><author>contact@crod.org (Chris Rodríguez Medina)</author><guid>https://crod.me/posts/suckless-ai/</guid><description>&lt;p&gt;AI is never going to be suckless. The models are huge, opaque, networked, and proprietary. The companies behind them go against almost everything the &lt;a href="https://suckless.org/philosophy/"&gt;suckless philosophy&lt;/a&gt; stands for, which is small, simple code you can actually read in an afternoon. And yet I use these tools every day. So this is me trying to make sense of that.&lt;/p&gt;
&lt;p&gt;If you have not run into suckless before, it is a project that ships things like a window manager (dwm), a terminal (st), and a launcher (dmenu). The whole point of them is that they are tiny. dwm is around 2,000 lines of C. You configure it by editing the source and compiling it again. There is no plugin system, because the source is the plugin system. The idea is not that small is good for its own sake. It is that you can hold the entire thing in your head. You can read it, you can change it, and nothing about it is a mystery to you, because you can see every line.&lt;/p&gt;
&lt;p&gt;AI is the exact opposite of that. A frontier model is hundreds of billions of numbers that no human has ever read or understood. Even the people who trained it cannot tell you why it said any particular thing. Whatever AI is, it is not transparent.&lt;/p&gt;
&lt;p&gt;So a lot of people in the Linux and free software circles I read land on a simple position. AI is the worst kind of black box, it is closed, it needs the network, it is monetized, and on top of all that it makes confident garbage. So avoid it. And honestly, they are not wrong about the tool. The big AI products really are that. Cursor, Copilot autocomplete, the IDE agents that bury your screen in suggestions, I do not want any of that near how I work. They go against every preference I have.&lt;/p&gt;
&lt;p&gt;Where I think that position goes wrong is the conclusion. &amp;ldquo;The tool is bad, so don&amp;rsquo;t use it&amp;rdquo; assumes you have to use it the way the companies want you to. You don&amp;rsquo;t. They want you inside their app, watching their suggestions. You do not have to be there.&lt;/p&gt;
&lt;p&gt;The more interesting question to me is whether the way you use AI can be suckless, even if the AI itself never will be. I think it can. It runs in the terminal, not some IDE plugin or browser tab. &lt;a href="https://claude.com/claude-code"&gt;Claude Code&lt;/a&gt; is the one I use. It only does something when I ask it to, there is no autocomplete sitting there guessing what I am typing. I read whatever it gives me, run it through my own eyes and my own tools, and throw it out if it is wrong. It reads and writes the same files I already control. In that shape it is just another thing in the terminal. I give it something, I read what comes back, I keep the good part.&lt;/p&gt;
&lt;p&gt;People throw the term vibe coding around like it is one thing, but there are two very different versions of it. One is passive. You let the model write whatever it wants, you do not really read it, you do not understand it, and you ship it because it ran. That is the part the suckless instinct is right to reject. It puts the AI between you and the problem and rewards you for not thinking. The other version is the one I actually do. I let it write the code, yes, but I am opinionated about it. I tell it exactly what I want, I read everything it gives back, I throw out what is wrong, and I have to actually understand what I am building or the output is just confident nonsense. Maybe that still makes me a vibe coder. If it does, I am a picky one. The typing is the part I handed off. The thinking and the judgment stayed with me. That is the whole difference, and it is the same difference as any unix tool. find does not think for you, awk does not think for you, and neither does this. Getting it right is still on you.&lt;/p&gt;
&lt;figure class="sideimg" style="float: none; width: auto; margin: 10px; padding: 6px; box-sizing: border-box;"&gt;
&lt;img src="https://crod.me/images/suckless-terminal.webp" alt="Screenshot of the claude command running in a terminal window" width="1893" height="1041" style="width: 100%; height: auto; display: block;"&gt;
&lt;figcaption style="text-align: center; font-size: 0.85em; font-style: italic; margin-top: 4px;"&gt;claude running in my terminal.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;In practice this is pretty boring, which is the point. I am on Void Linux running dwm, and claude runs in a terminal scoped to whatever project I am in. I am not sitting there hand-typing the code next to it. I direct it, it writes, and then I read what it did and keep it, change it, or throw it out. I drop into nvim when I want to read a file myself or fix something by hand. No plugin, no extension, no IDE, it is the same unix I have run for years with one more tool I can point at a problem. The work that moved off my plate is the typing. The work that did not is deciding what to build, reading what comes back, and being the one responsible when it is wrong.&lt;/p&gt;
&lt;p&gt;The scoping is the part that actually keeps it small, and it is almost embarrassingly low tech. Every project I work on has one plain text file sitting at the top of it that tells the tool what it needs to know about that project and nothing else. No database, no dashboard, no settings screen, just a markdown file I wrote by hand and can read in a couple of minutes. When I sit down to work, it reads that file and whatever code is actually in front of it, and that is the whole world as far as it is concerned. It does not see the rest of the projects sitting next to it. I decide what goes in that file, so I decide what it knows.&lt;/p&gt;
&lt;p&gt;That is the same trick the rest of my setup runs on. The config is text I can edit, the pieces are small, and I can keep the whole thing in my head. The projects that have something in common share one file at the top that holds whatever is true everywhere, and the rest just point at it instead of repeating it. Around the edges I have a few little shell scripts that run when the tool goes to change a file, so it stays inside the lines I drew. None of it is clever. It is plain files and small scripts boxing a huge tool into a shape I can actually live with. The model is gigantic and I cannot do anything about that. The part I own is the context I hand it and the box I keep it in, and that part is small, on purpose.&lt;/p&gt;
&lt;p&gt;I am not going to pretend this is actually suckless. It is not very close. The tool is still a giant black box on someone else&amp;rsquo;s computer, and I am still depending on a network and a company&amp;rsquo;s pricing. None of that is great. It is a trade I decided to make for what I get out of it, while keeping it boxed into the smallest corner of my workflow I can. The trick is to keep the tool small in how you use it even though the tool itself is enormous. Direct it, do not get directed by it. Check what it gives you. Do not let it creep into places it has no business being. AI is not going to become suckless. But you can. That part is up to you.&lt;/p&gt;</description></item><item><title>OpenBSD: Desktop to Server</title><link>https://crod.me/posts/desktop/</link><pubDate>Wed, 02 Oct 2024 00:00:00 +0000</pubDate><author>contact@crod.org (Chris Rodríguez Medina)</author><guid>https://crod.me/posts/desktop/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note (May 2026):&lt;/strong&gt; I no longer use OpenBSD as a desktop OS — I have since moved to &lt;a href="https://voidlinux.org/"&gt;Void Linux&lt;/a&gt;. I keep OpenBSD exclusively for servers. The desktop configuration below is preserved as a historical reference. See the &lt;a href="#server-configuration"&gt;&lt;em&gt;Server Configuration&lt;/em&gt;&lt;/a&gt; section at the end for my current server setup.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;In this post, I provide details on my after-installation OpenBSD configuration, software I use, and details on my Firefox configuration. This was written when I ran OpenBSD as my daily driver.&lt;/p&gt;
&lt;h2 id="afterboot8-extras--on-openbsd"&gt;afterboot(8) Extras — On Openbsd&lt;/h2&gt;
&lt;p&gt;These are some things I do after a clean installation of &lt;a href="https://openbsd.org"&gt;OpenBSD&lt;/a&gt; for desktop use. As the title alludes to, these are things I do after reading the &lt;em&gt;&lt;a href="https://man.openbsd.org/afterboot"&gt;afterboot&lt;/a&gt;&lt;/em&gt; man page. All of this info is in the man pages and &lt;a href="https://openbsd.org/faq/"&gt;FAQ&lt;/a&gt; already, but this document should lay out some other things you may want to have up and running in a dissectable manner.&lt;/p&gt;
&lt;h3 id="root-permissions-for-user"&gt;Root Permissions For &lt;em&gt;user&lt;/em&gt;&lt;/h3&gt;
&lt;pre&gt;&lt;code&gt;# echo &amp;quot;permit persist keepenv :wheel&amp;quot; &amp;gt;/etc/doas.conf
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;In case you did not add your user to the &lt;code&gt;:wheel&lt;/code&gt; group during the installation, you can do so like this:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# usermod -G wheel user
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Now you can do your whole system configuration as your user provided that you use the &lt;code&gt;doas&lt;/code&gt; command.&lt;/p&gt;
&lt;h3 id="wifi"&gt;WIFI&lt;/h3&gt;
&lt;p&gt;Identify your network card:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ ifconfig
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then, scan your local networks with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ ifconfig iwn0 scan # change &amp;quot;iwn0&amp;quot; for your network card
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Once you&amp;rsquo;ve identified your network card, edit the file &lt;code&gt;/etc/hostname.iwn0&lt;/code&gt; adjusting the final iwn0 with your card. Finally, add your WIFI ssid and wpakey:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;join wifiname wpakey wifipassword
join anotherwifi wpakey &amp;quot;anotherpass$123&amp;quot;
# randomize mac address on untrusted networks
lladdr random join wifi-name-cool wpakey &amp;quot;password-cool&amp;quot;
# ipv4
inet autoconf
# ipv6
inet6 autoconf
up
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="audio"&gt;Audio&lt;/h3&gt;
&lt;p&gt;This is not necessary, but if you have a USB audio device, this is what you would use for sndiod to recognize which audio device to use:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# echo &amp;quot;sndiod_flags=-f rsnd/0 -F rsnd/1&amp;quot; &amp;gt;/etc/rc.conf.local
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It may come useful when you least expect it.&lt;/p&gt;
&lt;h3 id="firewall"&gt;Firewall&lt;/h3&gt;
&lt;p&gt;The following is a sane firewall configuration for your average desktop user and it will be placed in &lt;code&gt;/etc/pf.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;set block-policy drop
set skip on lo
match in all scrub (no-df random-id max-mss 1440)
antispoof quick for egress
# block all traffic
block
# access ipv4 and ipv6
pass out quick inet
pass out quick inet6
# for use with mail transfer agents
pass in proto icmp
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Test your config and then apply:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# pfctl -fn /etc/pf.conf &amp;amp;&amp;amp; pfctl -f /etc/pf.conf
&lt;/code&gt;&lt;/pre&gt;
&lt;h2 id="performance-optimizations"&gt;Performance Optimizations&lt;/h2&gt;
&lt;p&gt;Since OpenBSD is more security oriented, the default performance can be lacking even on newer hardware. These steps should alleviate the speed issues.&lt;/p&gt;
&lt;h3 id="becoming-a-staff-member"&gt;Becoming a Staff Member&lt;/h3&gt;
&lt;p&gt;Add your user to the :staff group in order to access more of your system resources:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# usermod -L staff user
# usermod -G staff user
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="hyper-threading"&gt;Hyper Threading&lt;/h3&gt;
&lt;p&gt;One thing that will actually increase your performance is enabling hyper threading. It is disabled by default due to some &lt;a href="https://news.ycombinator.com/item?id=17350278"&gt;security concerns&lt;/a&gt;. My laptop at the time of writing is a relatively slow computer, so I can tell the difference. If your laptop is newer, say 2016 and up, you might not need it. You can test it with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# sysctl hw.smt=1
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;On a thinkpad x61, the performance is immediately noticeable. &lt;code&gt;firefox&lt;/code&gt; becomes usable with it enabled.&lt;/p&gt;
&lt;p&gt;Enable it permanently on next boot:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# echo hw.smt=1 &amp;gt;&amp;gt;/etc/sysctl.conf
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;For further performance optimizations, watch this &lt;a href="https://www.youtube.com/watch?v=f8lloCtrpdk"&gt;video&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="laptop-lid"&gt;Laptop Lid&lt;/h3&gt;
&lt;p&gt;I prefer to close the lid and work on my monitor. To close the lid without sending the laptop to sleep, you do the following:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# echo machdep.lidaction=0 &amp;gt;&amp;gt;/etc/sysctl.conf
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You can always run &lt;code&gt;zzz&lt;/code&gt; if you enabled &lt;code&gt;apmd&lt;/code&gt; whenever if you want to put your device to sleep, which does not require root permission in any case.&lt;/p&gt;
&lt;h3 id="sending-mail-with-opensmtpd"&gt;Sending mail with &lt;code&gt;OpenSMTPD&lt;/code&gt;&lt;/h3&gt;
&lt;p&gt;OpenBSD comes with &lt;a href="https://www.opensmtpd.org/"&gt;OpenSMTPD&lt;/a&gt; as the smtpd server and client. The following configuration will be used to send mail to the web from any accounts you wish to configure. Note that this configuration does not handle local mail. Read &lt;a href="https://man.openbsd.org/smtpd.conf"&gt;smtpd.conf(5)&lt;/a&gt; for that info.&lt;/p&gt;
&lt;p&gt;In &lt;code&gt;/etc/mail/smtpd.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# your credentials for your accounts go in this file (the &amp;quot;passwd&amp;quot; bit can be named anything):
table passwd file:/etc/mail/passwd
# configure your accounts' email, authentication protocol, port, and credentials (which
# are held in the &amp;quot;passwd&amp;quot; table) for opensmtpd to use when sending mail:
action &amp;quot;outbound_user&amp;quot; relay host smtp+tls://user@example.com:587 auth &amp;lt;passwd&amp;gt;
action &amp;quot;outbound_gmail&amp;quot; relay host smtp+tls://gmail@smtp.gmail.com:587 auth &amp;lt;passwd&amp;gt;
# tell smtpd to use those actions when sending mail with the following emails
match mail-from &amp;quot;user@example.com&amp;quot; for any action &amp;quot;outbound_user&amp;quot;
match mail-from &amp;quot;username@gmail.com&amp;quot; for any action &amp;quot;outbound_gmail&amp;quot;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Now, to edit &lt;code&gt;/etc/mail/passwd&lt;/code&gt;, you need to create the file and edit its permissions.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# touch /etc/mail/passwd
# chmod 640 /etc/mail/passwd
# chown root:_smtpd /etc/mail/passwd
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The credentials themselves &lt;code&gt;/etc/mail/passwd&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# the first argument matches the name you gave it: smtp+tls://user@example.com:587
# the second is the username for the mail server
# also, some email servers do not acclimate your username to the server. see example
# with the first email server, and gmail
user user@.example.com:yourpassword
gmail username:yourapppassword
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Everything should be in working order now. Test the configuration and restart the daemon to load your changes:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# smtpd -n &amp;amp;&amp;amp; rcctl restart smtpd
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Test your configuration:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ echo world | mail -r your@mail.org -s hello your@mail.org
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Now you should have OpenSMTPD working in order to send mail even when offline!&lt;/p&gt;
&lt;p&gt;My preferred mail client is listed in the &lt;a href="https://crod.me/posts/desktop#software"&gt;&lt;em&gt;software&lt;/em&gt;&lt;/a&gt; section.&lt;/p&gt;
&lt;h3 id="virtual-machines-vmd"&gt;Virtual Machines: &lt;code&gt;vmd&lt;/code&gt;&lt;/h3&gt;
&lt;p&gt;To use software not supported in OpenBSD, Windows programs with &lt;code&gt;wine&lt;/code&gt;, or maybe even test software you are not sure whether you trust, you cat use virtual machines as a secondary environment. The native hyper visor has no graphical support, meaning it can only connect to the console and control it through &lt;code&gt;ssh&lt;/code&gt; with your private interfaces. The substitute for using graphical applications is to use ssh with X11 Forwarding enabled or vnc. The latter is not worth the trouble to setup in my opinion.&lt;/p&gt;
&lt;p&gt;I will not go into much detail, for this you best visit the &lt;a href="https://openbsd.org/faq/"&gt;faq&lt;/a&gt;. To get networking working, add this to the firewall at &lt;code&gt;/etc/pf.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;match out on egress from 100.64.0.0/10 to any nat-to (egress)
pass in proto { udp tcp } from 100.64.0.0/10 to any port domain \
rdr-to 9.9.9.9 port domain
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;For our pf.conf the &amp;ldquo;9.9.9.9&amp;rdquo; part is the DNS server, Quad9&amp;rsquo;s to be specific. This could be changed to your ISPs DNS servers which are located at &lt;code&gt;/etc/resolv.conf&lt;/code&gt; and or any other DNS server.&lt;/p&gt;
&lt;p&gt;Next, we modify our VM settings at &lt;code&gt;/etc/vm.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;vm &amp;quot;alpine&amp;quot; {
disable # don't start up at boot
memory 4096M # max that can be used
disk &amp;quot;/home/user/vm/alpine.qcow2&amp;quot; # disk
cdrom &amp;quot;/home/user/isos/alpine-virt-3.17.3-x86_64.iso&amp;quot; # this cannot be a .img
owner user:user # control vm without root privs
local interface # give networking to the vm
}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Add the following lines to &lt;code&gt;/etc/sysctl.conf&lt;/code&gt; to allow the VM to use the internet:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;net.inet.ip.forwarding=1
net.inet6.ip6.forwarding=1
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="vm-guests"&gt;VM Guests&lt;/h3&gt;
&lt;p&gt;For my choice of VM operating system, I use &lt;a href="https://www.alpinelinux.org/"&gt;Alpine Linux&lt;/a&gt; as it is plenty sufficient for my needs. If you need something more feature-full, I would recommend &lt;a href="https://www.debian.org/"&gt;Debian Linux&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I usually like to configure X11 Forwarding on the VM so that I can use GUI programs on the native OS via any &lt;code&gt;ssh&lt;/code&gt; connection. It is not instant, but it is good for basic tasks. Now, to setup X11 Forwarding on your VM&amp;rsquo;s, you need to have Xorg installed, and you must activate it in &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt; on the VM side. Uncomment or add the following line to the mentioned file:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;X11Forwarding yes
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;And test on your local machine with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ ssh -X user@100.64.1.3 gui-program # 100.64.1.3 is the local ip your vm was given
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;In case it asks you that the host is missing some keys, run on your local machine:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ ssh-keygen -R 100.64.1.3
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="notes-on-alpine-linux-for-virtualization"&gt;Notes on Alpine Linux for Virtualization&lt;/h3&gt;
&lt;p&gt;Add this to &lt;code&gt;/boot/extlinux.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;console=ttyS0,115200
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It should be placed in the following highlighted section of the &lt;code&gt;/boot/extlinux.conf&lt;/code&gt; file:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;...
TIMEOUT 5
LABEL lts
...
APPEND root=.......... console=ttyS0,115200
...
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This allows the VM&amp;rsquo;s console mode to be matched with the VM guest, making the console mode much snappier.&lt;/p&gt;
&lt;p&gt;If you want to do X11 Forwarding, then on the VM running alpine, setup xorg:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# setup-xorg-base
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Next, install some packages:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# apk add wine git
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="using-wine"&gt;Using &lt;code&gt;wine&lt;/code&gt;&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;wine&lt;/code&gt; is a Windows program emulator that works well in alpine linux for 64 bit programs.&lt;/p&gt;
&lt;p&gt;Firstly, &lt;code&gt;wine&lt;/code&gt; can create separate environments to store your data and Windows programs on that folder. To create these environments for you to actually run .exe programs, you will need to run an environmental variable before executing your program or installer:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ WINEPREFIX=&amp;quot;$HOME/.wine/program-folder-name&amp;quot; WINEARCH=win32 wine setup.exe
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;To further explain, the WINEPREFIX is where the setup will extract its files and where everything will be saved from there on (except for .desktop files), and the WINEARCH=win32 specifies that the program is 32-bit. The latter only needs to be done once to specify that the WINEPREFIX is a 32-bit Windows system per se. After that, depending on whether it is a simple .exe or a setup wizard, you can launch it in various ways. I launch the programs by finding the local .exe in the WINEPREFIX folder and creating an alias for it for easy launching.&lt;/p&gt;
&lt;h2 id="notes-on-my-home"&gt;Notes On My $HOME&lt;/h2&gt;
&lt;p&gt;I try to keep things simple and rely on defaults whenever possible. Most of my programs are installed via the OpenBSD package manager. This configuration is universal for most unix systems that can build the following programs.&lt;/p&gt;
&lt;p&gt;From here on out, it is basically a poor man&amp;rsquo;s git server. I do not modify my system enough to justify trusting GitHub or setting up a git server. So this will do.&lt;/p&gt;
&lt;h3 id="x-configuration"&gt;X Configuration&lt;/h3&gt;
&lt;p&gt;Because OpenBSD&amp;rsquo;s &lt;code&gt;xorg&lt;/code&gt; fork has a built-in login screen, I do not go into the console directly, so, what you might place in a &lt;code&gt;.xinitrc&lt;/code&gt; and &lt;code&gt;.profile&lt;/code&gt; I condensed here into &lt;code&gt;$HOME/.xsession&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;export PATH=&amp;quot;$PATH:$HOME/.local/bin&amp;quot;
# make our oksh configuration visible in our X session
export ENV=$HOME/.kshrc
# Default programs:
export EDITOR=&amp;quot;vim&amp;quot;
export TERMINAL=&amp;quot;st&amp;quot;
export BROWSER=&amp;quot;firefox&amp;quot;
export READER=&amp;quot;zathura&amp;quot;
# ~/ Clean-up:
export XDG_CONFIG_HOME=&amp;quot;$HOME/.config&amp;quot;
export XDG_DATA_HOME=&amp;quot;$HOME/.local/share&amp;quot;
export XDG_CACHE_HOME=&amp;quot;$HOME/.cache&amp;quot;
export PASSWORD_STORE_DIR=&amp;quot;$XDG_DATA_HOME/passwords&amp;quot;
# UTF-8 everywhere
export LC_CTYPE=en_US.UTF-8
export LANG=en_US.UTF-8
# firefox
export MOZ_X11_EGL=1
export MOZ_ACCELERATED=1
export MOZ_WEBRENDER=1
export DBUS_SESSION_BUS_ADDRESS=&amp;quot;no&amp;quot; # this might break stuff
# Commands go after environment variables
# Disable caps and change it to compose key.
setxkbmap -option compose:caps,compose:nocaps
# Turn off caps lock if on since there is no longer a key for it.
xset -q | grep -q &amp;quot;Caps Lock:\s*on&amp;quot; &amp;amp;&amp;amp; xdotool key Caps_Lock
# Decrease key repeat delay to 300ms and increase key repeat rate to 50 per second.
xset r rate 300 50
# Blue light filter. Modify &amp;quot;-l&amp;quot; flag to your coordinates
redshift -l 1.0:-1.0 -t 4800:2700 -g 0.8 -m randr -v &amp;gt;/dev/null 2&amp;gt;&amp;amp;1 &amp;amp;
# Disable core dumps
ulimit -Sc 0 &amp;amp;
# no more bell sound
xset b off
# when X is loaded, check for external monitor on displayport.
# If detected, switch to it and shutdown laptop screen
xrandr | grep 'DP-2 connected' &amp;gt;/dev/null 2&amp;gt;&amp;amp;1 &amp;amp;&amp;amp;
xrandr --output DP-2 --auto --output LVDS-1 --off &amp;gt;/dev/null 2&amp;gt;&amp;amp;1
# Dwm status bar
slstatus &amp;amp;
# Wallpaper
xwallpaper --zoom ~/pics/bg &amp;amp;
# Exec WM
exec dwm
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="shell-oksh"&gt;Shell: &lt;a href="https://man.openbsd.org/ksh"&gt;oksh&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;oksh&lt;/code&gt; is the default shell for OpenBSD. There is a &lt;a href="https://github.com/ibara/oksh"&gt;port&lt;/a&gt; to run on other operating systems. &lt;code&gt;oksh&lt;/code&gt; has a default configuration which can be found at &lt;code&gt;/etc/ksh.kshrc&lt;/code&gt; that has some nice aliases to manage your jobs and a nice title bar configured.&lt;/p&gt;
&lt;p&gt;Source the file locally in &lt;code&gt;$HOME/.kshrc&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;. /etc/ksh.kshrc
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This is my configuration:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;set -o vi
alias \
v=&amp;quot;$EDITOR&amp;quot; \
dv=&amp;quot;doas $EDITOR&amp;quot; \
p=&amp;quot;nsxiv&amp;quot; \
z=&amp;quot;zathura&amp;quot; \
news='newsraft' \
t=&amp;quot;transmission-remote&amp;quot; \
mpa=&amp;quot;mpv --no-video&amp;quot; \
mpb=&amp;quot;mpv --save-position-on-quit&amp;quot; \
yt='yt-dlp --embed-metadata -i -f &amp;quot;bestvideo[height&amp;lt;=?1080][fps&amp;lt;=?60]+bestaudio/best[height&amp;lt;=?1080][fps&amp;lt;=?60]&amp;quot;' \
yta=&amp;quot;yt -f bestaudio/best -x --audio-format mp3 --embed-metadata --embed-thumbnail --audio-quality 320k&amp;quot; \
wttr='curl wttr.in/$LOCATION' \
ipp='curl ifconfig.me' \
sdn=&amp;quot;doas shutdown -h now&amp;quot;
# Bash-like syntax
PS1='$(print -n &amp;quot;`logname`@`hostname -s`:&amp;quot;; [[ &amp;quot;${PWD#$HOME}&amp;quot; != &amp;quot;$PWD&amp;quot; ]] &amp;amp;&amp;amp; print -n &amp;quot;~${PWD#$HOME}&amp;quot; || print -n &amp;quot;$PWD&amp;quot;; print &amp;quot;$ &amp;quot;)'
&lt;/code&gt;&lt;/pre&gt;
&lt;h2 id="software"&gt;Software&lt;/h2&gt;
&lt;h3 id="web-browser-firefox"&gt;Web Browser: &lt;a href="https://www.mozilla.org/firefox/"&gt;firefox&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;This browser does not truly respect your privacy until you tweak a couple of things. I go in depth in below in &lt;a href="https://crod.me/posts/desktop#working-with-firefox"&gt;Working with &lt;code&gt;Firefox&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="mail-client-aerc"&gt;Mail Client: &lt;a href="https://aerc-mail.org/"&gt;aerc&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;aerc&lt;/code&gt;&amp;rsquo;s defaults are quite sensible, so most of my configuration comes from how I send and receive mail. The following account configuration example is using &lt;code&gt;aerc&lt;/code&gt;&amp;rsquo;s built-in mail fetching and sending protocols:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;[john]
source = imaps://user:PasswordExample123@mail.example.com
outgoing = smtps://user:PasswordExample123@mail.example.com
default = INBOX
from = &amp;quot;John Doe&amp;quot; &amp;lt;john@example.com&amp;gt;
cache-headers = true
[cath]
source = imaps://cath:PasswordExample123@mail.example.com
outgoing = smtps://cath:PasswordExample123@mail.example.com
default = INBOX
from = &amp;quot;Cath Doe&amp;quot; &amp;lt;cath@example.com&amp;gt;
cache-headers = true
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The passwords are encrypted by default if you follow the wizard on startup.&lt;/p&gt;
&lt;p&gt;If you have OpenSMTPD setup, or an equivalent like Postfix, you can send mail with &lt;code&gt;sendmail&lt;/code&gt; linked in &lt;code&gt;aerc&lt;/code&gt;&amp;rsquo;s account.conf file. Just change the &lt;em&gt;outgoing&lt;/em&gt; section to the following for one or multiple accounts. And for offline mail, use your Maildir folder to access your offline mail. Modify the &lt;em&gt;source&lt;/em&gt; section and add your mail fetch command for aerc to run automatically:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;[john]
check-mail-cmd = fdm fetch
source = maildir://~/mail
outgoing = /usr/sbin/sendmail
default = INBOX
from = &amp;quot;John Doe&amp;quot; &amp;lt;john@example.com&amp;gt;
cache-headers = true
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="mail-fetcher-fdm"&gt;Mail Fetcher: &lt;a href="https://github.com/nicm/fdm"&gt;fdm&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;fdm&lt;/code&gt; is easier to use than the more popular alternative &lt;code&gt;mbsync/isync&lt;/code&gt; and is developed by a &lt;a href="https://github.com/tmux/tmux"&gt;&lt;code&gt;tmux&lt;/code&gt;&lt;/a&gt; developer which was first developed for OpenBSD.&lt;/p&gt;
&lt;p&gt;The default config file is found in &lt;code&gt;$HOME/.fdm.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# define your maildir location
action &amp;quot;inbox&amp;quot; maildir &amp;quot;%h/mail&amp;quot;
# configure which accounts to fetch mail from
account &amp;quot;example&amp;quot; imaps server &amp;quot;example.com&amp;quot; user &amp;quot;user@example.com&amp;quot; pass &amp;quot;yourpassword&amp;quot;
account &amp;quot;gmail&amp;quot; imaps server &amp;quot;imap.gmail.com&amp;quot; user &amp;quot;yourGmail@gmail.com&amp;quot; pass &amp;quot;yourgmailapppassword&amp;quot;
# every mail fetched goes to the defined maildir folder
match all action &amp;quot;inbox&amp;quot;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;To set the proper permissions on the file, run:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;$ chmod 600 .fdm.conf&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;And that should be it. Beware though, by default, fdm fetches your mail from your server onto your device, meaning mail will be deleted on your server and stored locally. You can now fetch and manage your mail with fdm and your preferred mail client. To fetch your mail:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;$ fdm fetch&lt;/code&gt;&lt;/p&gt;
&lt;h3 id="videomusic-player-mpv"&gt;Video/Music Player: &lt;a href="https://mpv.io"&gt;mpv&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The configuration file can be found in &lt;code&gt;$HOME/.config/mpv/mpv.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# choose english audio if available
alang=eng
# turn 5.1 surround to 2.0 stereo
audio-channels=stereo
# set the highest quality video to 1080p 60fps
ytdl-format=bestvideo[height&amp;lt;=?1080][fps&amp;lt;=?60]+bestaudio/best[height&amp;lt;=?1080][fps&amp;lt;=?60]
# sane beginning size
autofit=50%
# less output
quiet
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;And to change a couple of keyboard bindings, change &lt;code&gt;$HOME/.config/mpv/input.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# vim bindings
l seek 5
h seek -5
j seek -60
k seek 60
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="other-software"&gt;Other Software&lt;/h3&gt;
&lt;p&gt;Here I will put software that I do not modify or have personal configurations as such.&lt;/p&gt;
&lt;h4 id="window-manager-dwm"&gt;Window Manager: &lt;a href="https://dwm.suckless.org/"&gt;dwm&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;A very small and concise window manager. I run &lt;code&gt;dwm&lt;/code&gt; with no patches. Just bindings and default to floating mode.&lt;/p&gt;
&lt;h4 id="terminal-st"&gt;Terminal: &lt;a href="https://st.suckless.org/"&gt;st&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;A very feature-less terminal that just works. For &lt;code&gt;st&lt;/code&gt;, I use the &lt;a href="https://st.suckless.org/patches/scrollback/"&gt;scrollback&lt;/a&gt; patch to enable scrolling.&lt;/p&gt;
&lt;h4 id="dynamic-menu-dmenu"&gt;Dynamic Menu: &lt;a href="https://tools.suckless.org/dmenu"&gt;dmenu&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Highly versatile menu used for scripting. Look at the &lt;a href="https://tools.suckless.org/dmenu/scripts/"&gt;dmenu scripts&lt;/a&gt; section for inspiration.&lt;/p&gt;
&lt;h4 id="text-editing-and-text-composer-vi-and-vim"&gt;Text Editing and Text Composer: &lt;a href="https://man.openbsd.org/vi.1"&gt;vi&lt;/a&gt; and &lt;a href="https://www.vim.org/"&gt;vim&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;&lt;code&gt;vim&lt;/code&gt; for composing text as it supports utf-8 and &lt;code&gt;vi&lt;/code&gt; for everything else.&lt;/p&gt;
&lt;h4 id="musicaudio-player-cmus-and-mpv"&gt;Music/Audio Player: &lt;a href="https://cmus.github.io/"&gt;cmus&lt;/a&gt; and &lt;a href="https://mpv.io/"&gt;mpv&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;I use &lt;code&gt;cmus&lt;/code&gt; for local storage and &lt;code&gt;mpv&lt;/code&gt; for web based music or podcast.&lt;/p&gt;
&lt;p&gt;Checkout &lt;a href="https://somafm.com/"&gt;SomaFM&lt;/a&gt; if you haven&amp;rsquo;t already. You can stream the radio stations on the terminal with &lt;code&gt;mpv&lt;/code&gt;.&lt;/p&gt;
&lt;h4 id="rss-reader-newsraft"&gt;RSS Reader: &lt;a href="https://codeberg.org/newsraft/newsraft"&gt;newsraft&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Great tool to keep you off the browser.&lt;/p&gt;
&lt;h4 id="torrent-client-transmission"&gt;Torrent Client: &lt;a href="https://transmissionbt.com/"&gt;Transmission&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;There are GUI and TUI interfaces out there, but the terminal client &lt;code&gt;transmission-remote&lt;/code&gt; works for me.&lt;/p&gt;
&lt;h4 id="presentations-sent"&gt;Presentations: &lt;a href="https://tools.suckless.org/sent/"&gt;sent&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;The easiest way to make presentations; just a paragraph per page. It also supports images. I use the &lt;a href="https://tools.suckless.org/sent/patches/pdf/"&gt;pdf patch&lt;/a&gt; in order to compile it into a pdf and be able to send it to another person.&lt;/p&gt;
&lt;h4 id="documentpdf-viewer-zathura"&gt;Document/PDF Viewer: &lt;a href="https://pwmt.org/projects/zathura/"&gt;zathura&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;A great document reader that remembers your reading progress, shows tabs, and reloads files automatically for work with TeX. After installing some &lt;a href="https://pwmt.org/projects/zathura/plugins/"&gt;plugins&lt;/a&gt; you can open PDF, Postscript, DJVU, EPUB, and more!&lt;/p&gt;
&lt;h4 id="writing-documents-tex"&gt;Writing Documents: &lt;a href="https://tug.org/texlive/"&gt;TeX&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;To write documents in PDF format, I use TeX, the precursor of the popular &lt;a href="https://www.latex-project.org/"&gt;LaTeX&lt;/a&gt;. &lt;a href="https://petr.olsak.net/optex/"&gt;OpTeX&lt;/a&gt; is a great addition to use more advanced features with the same small footprint of TeX.&lt;/p&gt;
&lt;h4 id="office-365-replacement-libreoffice"&gt;Office 365 Replacement: &lt;a href="https://www.libreoffice.org/"&gt;Libreoffice&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;The open source, free alternative to Office 365. I do not create content with this, but this will take care of the occasional Microsoft document you have to open.&lt;/p&gt;
&lt;h4 id="image-viewer-nsxiv"&gt;Image Viewer: &lt;a href="https://nsxiv.codeberg.page/"&gt;nsxiv&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Simple Image viewer with a nice thumbnail mode.&lt;/p&gt;
&lt;h4 id="image-editing-gimp-and-imagemagick"&gt;Image Editing: &lt;a href="https://www.gimp.org/"&gt;gimp&lt;/a&gt; and &lt;a href="https://imagemagick.org/"&gt;ImageMagick&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;&lt;code&gt;gimp&lt;/code&gt; for photoshop-like image editing and &lt;code&gt;magick&lt;/code&gt; for simple edits in the command line.&lt;/p&gt;
&lt;h2 id="working-with-firefox"&gt;Working with Firefox&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;firefox&lt;/code&gt; is known to &lt;a href="https://spyware.neocities.org/articles/firefox"&gt;phone home&lt;/a&gt; back to their servers. We can mitigate the tracking by customizing our profile through a &lt;em&gt;user.js&lt;/em&gt; file.&lt;/p&gt;
&lt;p&gt;Note that you should be able to configure your &lt;code&gt;firefox&lt;/code&gt; straight from this document without having to fall back to other resources. Of course, I encourage you to read the documentation for these projects, but, if you are in a hurry, this will do fine.&lt;/p&gt;
&lt;h3 id="userjs"&gt;user.js&lt;/h3&gt;
&lt;p&gt;For this configuration, you will need the &lt;a href="https://github.com/arkenfox/user.js"&gt;arkenfox user.js&lt;/a&gt; file in your profile. Your profile is your advanced configuration for &lt;code&gt;firefox&lt;/code&gt;. If you do not know where your profile is stored, go to &lt;em&gt;about:profiles&lt;/em&gt; in the url bar. Once you&amp;rsquo;re in that directory, fetch the user.js file:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ curl -sL &amp;quot;https://raw.githubusercontent.com/arkenfox/user.js/master/user.js&amp;quot; &amp;gt; user.js
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Read the &lt;a href="https://github.com/arkenfox/user.js/wiki/"&gt;arkenfox wiki&lt;/a&gt;, it details the important bits about the user.js file and what problems you might be faced with in the future. Personally, I&amp;rsquo;ve done everything with this user.js without any issues, what might break stuff is any further privacy configurations added to the &lt;em&gt;user.js&lt;/em&gt; file, which will be explained in a bit.&lt;/p&gt;
&lt;p&gt;Now, I append more settings to the user.js from these sources:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://wiki.archlinux.org/title/Firefox/Privacy"&gt;Arch Linux Wiki&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sciops.net/information/technology/firefox"&gt;Sciops&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Here is my &lt;a href="https://crod.me/files/extra.js"&gt;extra.js&lt;/a&gt; which you can put in the original user.js. If you &lt;strong&gt;do not&lt;/strong&gt; have a router of some sort with dns blocking capabilities, uncomment the last line and change the second-to-last value to 2. This will help route your dns queries through a more trustworthy source.&lt;/p&gt;
&lt;p&gt;If the additional user.js configurations cause some mishap on your browsing, you can do without the extra.js.&lt;/p&gt;
&lt;h3 id="extensions"&gt;Extensions&lt;/h3&gt;
&lt;h4 id="ublock-origin"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/"&gt;uBlock Origin&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;If you could only have one extension installed to your browser, uBlock Origin would be the one. It is, as the description says, a wide-spectrum blocker.&lt;/p&gt;
&lt;p&gt;Set up your preferred &lt;a href="https://github.com/gorhill/uBlock/wiki/Blocking-mode"&gt;blocking mode&lt;/a&gt;. There are a couple of them, ranging from very easy, to hard mode. I opt for the &lt;a href="https://github.com/gorhill/uBlock/wiki/Blocking-mode:-easy-mode"&gt;&lt;em&gt;Easy&lt;/em&gt; mode&lt;/a&gt;.&lt;/p&gt;
&lt;h4 id="skip-redirect"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/skip-redirect/"&gt;Skip Redirect&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;This add-on skips intermediary pages found in redirect links to go straight to the target. These type of links are solely used to track you.&lt;/p&gt;
&lt;p&gt;If you use the &lt;a href="https://web.archive.org/"&gt;web archive&lt;/a&gt;, you need to add an exception rule, which can be done so in the &lt;strong&gt;No-skip-urls-list&lt;/strong&gt; section of the extension:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;web.archive.org/
&lt;/code&gt;&lt;/pre&gt;
&lt;h4 id="true-sight"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/detect-cloudflare-plus/"&gt;True Sight&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Used to find out what content delivery network (CDN) is serving your content. This is a great tool for informational purposes.&lt;/p&gt;
&lt;h4 id="vimium"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/vimium-ff/"&gt;Vimium&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Adds vim-like bindings to your browsing experience. This is one of the most minimal and functional vim keybinding add-on for &lt;code&gt;firefox&lt;/code&gt;.&lt;/p&gt;
&lt;h4 id="privacy-oriented-origin-policy"&gt;&lt;a href="https://claustromaniac.github.io/poop/"&gt;Privacy-Oriented Origin Policy&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;This add-on replaces disabling Referrer Headers in the user.js allowing you to whitelist affected pages. I run it in &lt;em&gt;aggressive&lt;/em&gt; mode with rare site breakage. The &lt;a href="https://claustromaniac.github.io/poop/"&gt;P.O.O.P&lt;/a&gt; website explains it clearly, though.&lt;/p&gt;
&lt;h4 id="flagfox"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/flagfox/"&gt;Flagfox&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Another great informational add-on that shows you a flag in the url bar with the country of origin of where the server is being hosted. It can also pipe the current url to many services.&lt;/p&gt;
&lt;h4 id="localcdn"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/localcdn-fork-of-decentraleyes/"&gt;LocalCDN&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Loads CDN resources locally to speed up load times and connect to these external resources less often.&lt;/p&gt;
&lt;h4 id="play-with"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/play-with/"&gt;play-with&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;I use this add-on to pipe videos, including YouTube and audio to &lt;code&gt;mpv&lt;/code&gt;.&lt;/p&gt;
&lt;h4 id="list-feeds"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/list-feeds/"&gt;List Feeds&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Searches for RSS and Atom feeds in a page and lists them in the url icon.&lt;/p&gt;
&lt;h4 id="open-in-sci-hub"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/open-in-sci-hub/"&gt;Open in Sci-Hub&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Puts a &lt;a href="https://sci-hub.st/"&gt;Sci-Hub&lt;/a&gt; icon in the url bar when visiting paywalled academic articles to easily view it in the Sci-Hub database.&lt;/p&gt;
&lt;h3 id="openbsd-specifics"&gt;OpenBSD Specifics&lt;/h3&gt;
&lt;h4 id="unveil-directories"&gt;Unveil directories&lt;/h4&gt;
&lt;p&gt;If you are using OpenBSD, you would know that &lt;code&gt;firefox&lt;/code&gt; can only see directories in which you give it access to. To edit this website locally, I do:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# echo &amp;quot;~/content r&amp;quot; &amp;gt;&amp;gt;/etc/firefox/unveil.content
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Once you restart &lt;code&gt;firefox&lt;/code&gt; you should be able to have read access to everything in the &lt;code&gt;content&lt;/code&gt; folder.&lt;/p&gt;
&lt;h4 id="unveil-software"&gt;Unveil Software&lt;/h4&gt;
&lt;p&gt;If you want to read pdf&amp;rsquo;s directly from a document viewer instead of the &lt;code&gt;firefox&lt;/code&gt; pdf viewer, you need to &lt;a href="https://why-openbsd.rocks/fact/unveil/"&gt;&lt;em&gt;unveil&lt;/em&gt;&lt;/a&gt;&lt;a href="https://man.openbsd.org/unveil.2"&gt;(2)&lt;/a&gt; the package itself, as well as making it a &amp;ldquo;default application&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;To &lt;em&gt;unveil&lt;/em&gt; your preferred document reader, do the following:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# echo &amp;quot;/usr/local/bin/zathura rx&amp;quot; &amp;gt;&amp;gt;/etc/firefox/unveil.main
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Notice the file we are writing to. It will be &lt;code&gt;unveil.main&lt;/code&gt; instead of &lt;code&gt;unveil.content&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;firefox&lt;/code&gt; is now able to read and execute &lt;code&gt;zathura&lt;/code&gt;, but it does not know it to be the pdf viewer. To make &lt;code&gt;firefox&lt;/code&gt; understand so, we do the following:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ echo &amp;quot;application/pdf; /usr/local/bin/zathura %s&amp;quot; &amp;gt;~/.mailcap
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Restart &lt;code&gt;firefox&lt;/code&gt;, go to the settings page, search for &lt;strong&gt;default applications&lt;/strong&gt;, and you can now choose the option that says &lt;strong&gt;Use system default application&lt;/strong&gt; next to the pdf section. You should now be able to open pdf docs directly from &lt;code&gt;firefox&lt;/code&gt; with a document viewer.&lt;/p&gt;
&lt;h4 id="video-conferences"&gt;Video Conferences&lt;/h4&gt;
&lt;p&gt;If this is something you must do, it can be setup quite easily. You need to permit video and audio recording down to the kernel and make your webcam usable by your user:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# sysctl kern.audio.record=1
# sysctl kern.video.record=1
# chown user /dev/video0
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The &lt;code&gt;chown&lt;/code&gt; bit only needs to be done once for your device. After a reboot, the only steps you would need to take are the first two commands. Also, the webcam can also be &lt;code&gt;/dev/video1&lt;/code&gt; for example.&lt;/p&gt;
&lt;h2 id="resources"&gt;Resources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://suckless.org/rocks/"&gt;Software that Rocks&lt;/a&gt; — Brought to you by &lt;a href="https://suckless.org/"&gt;Suckless&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@TheOpenBSDguy"&gt;The OpenBSD Guy&lt;/a&gt; — More OpenBSD guides.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://why-openbsd.rocks/fact/"&gt;Why OpenBSD Rocks&lt;/a&gt; — Stuff that rocks.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://permacomputing.net/"&gt;Permacomputing&lt;/a&gt; — Keepin&amp;rsquo; it sensible.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.k58.uk/openbsd.html"&gt;Running OpenBSD on your laptop is really hard (not)&lt;/a&gt; — It really isn&amp;rsquo;t.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="server-configuration"&gt;Server Configuration&lt;/h2&gt;
&lt;p&gt;This is my current use for OpenBSD: a lean web server running &lt;code&gt;httpd&lt;/code&gt; behind &lt;code&gt;relayd&lt;/code&gt; for TLS termination. The following is the setup for a static site — the same stack this website runs on.&lt;/p&gt;
&lt;h3 id="pf-firewall"&gt;pf Firewall&lt;/h3&gt;
&lt;p&gt;A server needs a tighter firewall than a desktop. Block everything; only permit SSH, HTTP, and HTTPS:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;set block-policy drop
set skip on lo
match in all scrub (no-df random-id max-mss 1440)
antispoof quick for egress
block all
pass in on egress proto tcp from any to any port { 22 80 443 }
pass out all
pass in proto icmp
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Test and apply:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# pfctl -fn /etc/pf.conf &amp;amp;&amp;amp; pfctl -f /etc/pf.conf
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="httpd"&gt;httpd&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;httpd&lt;/code&gt; listens on port 80, handles ACME challenges, and serves the static site. In &lt;code&gt;/etc/httpd.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;server &amp;quot;example.com&amp;quot; {
listen on * port 80
root &amp;quot;/htdocs/example.com&amp;quot;
location &amp;quot;/.well-known/acme-challenge/*&amp;quot; {
root &amp;quot;/acme&amp;quot;
request strip 2
}
}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Enable and start:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# rcctl enable httpd
# rcctl start httpd
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="relayd--tls-termination"&gt;relayd — TLS Termination&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;relayd&lt;/code&gt; listens on port 443, terminates TLS, and forwards to &lt;code&gt;httpd&lt;/code&gt; on port 80. It also injects security headers. In &lt;code&gt;/etc/relayd.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;ip4 = &amp;quot;YOUR.IP.HERE&amp;quot;
http protocol &amp;quot;wwwtls&amp;quot; {
match response header set &amp;quot;Strict-Transport-Security&amp;quot; \
value &amp;quot;max-age=31536000; includeSubDomains&amp;quot;
match response header set &amp;quot;X-Frame-Options&amp;quot; value &amp;quot;DENY&amp;quot;
match response header set &amp;quot;X-Content-Type-Options&amp;quot; value &amp;quot;nosniff&amp;quot;
match response header set &amp;quot;Content-Security-Policy&amp;quot; \
value &amp;quot;default-src 'self'&amp;quot;
pass
}
relay &amp;quot;www4tls&amp;quot; {
listen on $ip4 port 443 tls
protocol &amp;quot;wwwtls&amp;quot;
forward to 127.0.0.1 port 80
}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;code&gt;relayd&lt;/code&gt; looks for the certificate at &lt;code&gt;/etc/ssl/example.com.crt&lt;/code&gt; by default — symlink your fullchain there.&lt;/p&gt;
&lt;h3 id="acme-client--lets-encrypt"&gt;acme-client — Let&amp;rsquo;s Encrypt&lt;/h3&gt;
&lt;p&gt;In &lt;code&gt;/etc/acme-client.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;authority letsencrypt {
api url &amp;quot;https://acme-v02.api.letsencrypt.org/directory&amp;quot;
account key &amp;quot;/etc/acme/letsencrypt-privkey.pem&amp;quot;
}
domain example.com {
alternative names { www.example.com }
domain key &amp;quot;/etc/ssl/private/example.com.key&amp;quot;
domain full chain certificate &amp;quot;/etc/ssl/example.com.fullchain.pem&amp;quot;
sign with letsencrypt
}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Obtain the certificate, then symlink for &lt;code&gt;relayd&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# acme-client example.com
# ln -s /etc/ssl/example.com.fullchain.pem /etc/ssl/example.com.crt
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Add a cron job for automatic renewal:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;0 0 * * * acme-client example.com &amp;amp;&amp;amp; rcctl reload relayd
&lt;/code&gt;&lt;/pre&gt;
&lt;h3 id="deploying-a-static-site"&gt;Deploying a Static Site&lt;/h3&gt;
&lt;p&gt;I push the Hugo &lt;code&gt;public/&lt;/code&gt; directory from my desktop via &lt;code&gt;rsync&lt;/code&gt;, then run a sync script on the server via &lt;code&gt;doas&lt;/code&gt;. On the server, &lt;code&gt;/home/user/sync.sh&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code class="language-sh"&gt;#!/bin/sh
set -e
rm -rf /var/www/htdocs/example.com/*
cp -R /home/user/public/. /var/www/htdocs/example.com/
chown -R www:daemon /var/www/htdocs/example.com
chmod -R a-xw /var/www/htdocs/example.com
chmod -R u+xwX /var/www/htdocs/example.com
chmod -R g+rX /var/www/htdocs/example.com
rcctl restart httpd relayd
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;In &lt;code&gt;doas.conf&lt;/code&gt;, permit the deploy user to run the script without a password:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;permit nopass user cmd /home/user/sync.sh
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;From the desktop:&lt;/p&gt;
&lt;pre&gt;&lt;code class="language-sh"&gt;hugo --minify --cleanDestinationDir
rsync -avz --delete public/ user@server:/home/user/public/
ssh -t user@server doas /home/user/sync.sh
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The &lt;code&gt;-t&lt;/code&gt; flag is required — &lt;code&gt;doas&lt;/code&gt; needs a tty even with &lt;code&gt;nopass&lt;/code&gt; set.&lt;/p&gt;</description></item></channel></rss>