Bastille: FreeBSD Jails Management
bastillebsd.org
bastillebsd.org
I would argue that said users have never heard of UNSHARE(1) either, although Linux pretty much wipes the floor with anything else when it comes to containers. You can use UNSHARE(1) to create your container, extract a base image of your preferred distribution, configure it and start an instance. Heck, you can even create and package a shell script that does all the above for you. Nobody does that on Linux even though UNSHARE(1) (and friends) are very much finished products. They are not the products people want, that is, application specific containerization solutions like Docker, or something that can be easily deployed at scale in a reproducible and compliant way.
I've heard of jails but haven't used BSD enough to ever use them. (And I'm not old enough to have ever mucked with zones. My Solaris boat anchors were just toys for a teen collector.)
A quick illustration of commands that really ought to be on the landing page and not hidden behind three layers of hyperlinks if you want to pique potential users' interest:
ishmael ~ # bastille create folsom 11.2-RELEASE 10.8.62.1
RELEASE: 11.2-RELEASE.
NAME: folsom.
IP: 10.8.62.1.
ishmael ~ # bastille cmd folsom 'ps -auxw'
[folsom]:
USER PID %CPU %MEM VSZ RSS TT STAT STARTED TIME COMMAND
root 71464 0.0 0.0 14536 2000 - IsJ 4:52PM 0:00.00 /usr/sbin/syslogd -ss
root 77447 0.0 0.0 16632 2140 - SsJ 4:52PM 0:00.00 /usr/sbin/cron -J 60 -s
root 80591 0.0 0.0 18784 2340 1 R+J 4:53PM 0:00.00 ps -auxw
ishmael ~ # bastille stop folsom
[folsom]:
folsom: removed
ishmael ~ # bastille destroy folsom
Deleting Jail: folsom.
Note: jail console logs not destroyed.
/usr/local/bastille/logs/folsom_console.logI'm interested in jails because I have a BSD need, so this is timely but starting with misinformation puts off.
Not a great layout. Not the fault if jails though.
In fact LXC/LXD containers in Ubuntu are exactly this by default.
On the other hand this stuff really isn't rocket science and shouldn't be as complicated as we are making it.
This looks more like something in the spirit of systemd-nspawn plus templates if I'd compare it to the Linux domain.
Yes, of course, there are ways around that, but it just doesn’t make economical sense for most organizations.
I run a research cluster, and here’s how I built it.
Firewall+DNS= OpenBSD(pf)
File server(NFS) = FreeBSD (ZFS)
Compute nodes = Fedora latest with some optimizations.
Identity provider = CentOS( FreeIPA)
Database server = CentOS(Postgres)
Web servers = CentOS podman(nginx)
FreeBSD for ZFS fileserver has been solid and dependable like nothing I have ever worked with before - it is hard to believe that it is free in cost and open source. I probably would not even think about running FreeBSD for compute nodes because it is not its thing.... almost all research software in the wild are being written with Linux in mind.
https://www.daemonology.net/blog/2018-12-26-the-many-ways-to...
This feature seems to be missing here.
I know that jails do support cpu and memory limits (via rctl).