Skip to content
← The project behind this paper

Bedrock Computing: Why Infrastructure is Civil Architecture

Reflections from Systems Administration, FreeBSD Hardening, and the Philosophy of Durable IT

Joshua M. Abrams
byJoshua M. Abrams
August 2024·8 min read·Technical Systems
Topics:Systems Administration,Security,Linux,FreeBSD,Architecture
Overview

In an era dominated by ephemeral microservices and abstracted serverless runtimes, foundational systems engineering is frequently neglected. An argument for mastering kernel internals, network security, and deterministic operating system architecture.

Figure 1.1 · Ephemeral Container Churn vs. Deterministic Bedrock Architecture
Modern Cloud Anti-Pattern~1.5 GB Footprint
Web UI / Ephemeral JavaScript Framework
14,000+ Unvetted NPM Dependency Tree
Docker / OCI Container Layer + Libc Bloat
Systemd + 400 Background Daemons
Linux Monolithic Kernel (30M+ LOC)
Bare Hardware / Ring 0
Omni Bedrock Computing Standard< 15k LOC TCB
Sandboxed LibOS Environments (Alpine Rootfs / Wasm)
PID 1 Init Supervisor (Go Runtime <15k LOC)
Deterministic Memory Isolation & Zero-RPC Invariant
Exokernel Resource Multiplexing (Hardware-Enforced)
Bare Metal Silicon / RISC-V / x86_64
Figure 1.1: Architectural comparison between transient software bloat and bedrock computing. By replacing 30 million lines of mutable monolithic kernel code with a formally verified, minimal trusted computing base (<15k LOC), systems achieve decade-scale operational stability.

1. The Vanishing Art of Bedrock Engineering

The modern software industry has developed a dangerous habit of stacking abstractions upon abstractions. Developers deploy multi-gigabyte container clusters to accomplish tasks that could be handled by a single well-tuned FreeBSD jail or a lean Linux daemon.

When the foundational layers—the IP stack, the filesystem journal, memory allocation pools, and permission ACLs—are treated as black boxes, systemic vulnerabilities inevitably proliferate.

2. Security as a Posture, Not a Feature

True security is not a third-party plugin or an enterprise dashboard; it is the natural consequence of simplicity, isolation, and defensive architecture. By enforcing strict least-privilege paradigms, deterministic build pipelines, and constant auditability, systems become inherently resilient to intrusion.

References & Verified Sources
McKusick, M. K. (2014)
The Design and Implementation of the FreeBSD Operating System. Addison-Wesley.
Saltzer, J. H., & Schroeder, M. D. (1975)
The protection of information in computer systems. Proceedings of the IEEE.
Free Weekly Dispatch
Enjoyed this technical monograph?

Get the 5 things I'm building, engineering, and reading every Friday.

Join Free Dispatch