The huge practical difference right now is that on Linux, Docker and LXC (as in linuxcontainers.org) provide a high-level, fairly opinioned framework and set of infrastructure pieces to build, run and manage containers — and there are no fully equivalent tools on BSD, at least none that are as featureful or mature.
If you want to do containerized deploys on BSD, you'll be writing scripts that set up jails, call rctl, set kernel parameters with sysctl, and so on. There's ezjail [1], but it's nowhere near Docker in terms of scope.
I actually wish there was something on Linux that was less monolithic and better designed than Docker. Its image management is badly designed and annoying to use, and after all this time it still suffers from design flaws such as needing to be the parent of all containers (completely unnecessary given that we have cgroups).
[1] https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/j...
I'm working on a simple FreeBSD jail runner: https://github.com/myfreeweb/sandblast The main idea is machine-friendly configuration: your higher level software (PaaS, CI, etc.) produces a JSON config and pipes it to sandblast, which runs a script in the container.
in jail.conf i just have
stud {
path = "/usr/local/jails/jail_name";
ip4 = "inherit";
host.hostname = "jail_name.example.net";
securelevel = 4;
devfs_ruleset = 10;
exec.start = "/bin/service --config=/etc/service.conf";
mount.devfs;
exec.system_jail_user;
exec.jail_user=jail_name;
exec.poststart="/usr/local/bin/jail_ipfw";
}
(ok, i also setup a devfs rule, because i had issues with built in ones and various patch levels of FreeBSD -- and my service needs access to /dev/random)The only non-obvious thing is you need /libexec/ld-elf.so.1 in order to run dynamically linked libraries.
There's also the PC-BSD Warden. With it, one generally does not write scripts to "set up jails, call rctl, set kernel parameters with sysctl".
See the PC-BSD 10.1 Handbook chapter 8:
* http://download.pcbsd.org/iso/10.1-RELEASE/amd64/docs/html/c...