FreeBSD Jails Containers
vermaden.wordpress.com
vermaden.wordpress.com
If you're just looking for an orchestrator capable of running FreeBSD jails, take a look at Nomad (Disclaimer: I work at HashiCorp, opinions my own, etc.)
There could be a similar kind of mapping on FreeBSD.
How does Nomad handle scaling? I'm thinking of a new project, I'd like to have the equivalent of HPA that easily scales to zero on custom metrics and a cluster autoscaler that can easily add heterogenous nodes as necessary. Even better if it can work with MacOS VMs.
In terms of autoscaling there's the Nomad Autoscaler[1][2] that is super flexible, can get metrics from a bunch of sources, do custom queries, and perform actions (everything is via plugins, so even if your current stack isn't already supported, it's easy to add) like add extra nodes or add more instances of jobs.
0 - https://www.hashicorp.com/c2m
I like the isolation for my own bespoke home network, but does it work well in production set up’s?
* https://www.freshports.org/misc/compat12x/
See further:
* https://www.freshports.org/misc/compat11x/
* https://www.freshports.org/misc/compat10x/
[…]
All in all of all the concerns I'd have about using jails in a production environment, dealing with different major versions is not on that list.
As was pointed out, you can run binaries from a FreeBSD version (4) that's probably older than most posters here. Still not seeing what the big fuss is about.
And to be clear, you can not take a complete userland from 4.x. You have to reinstall your application on a newer userland with compat shims when you change the kernel.
Ironically enough, the Linux syscall compat layer in FreeBSD may give you more stability here.
You have to reinstall your application on a newer userland with compat
shims when you change the kernel.
No, you don't. You can absolutely take a jail based on a previous version of FreeBSD and run it on a newer version. I've not tried going as far back as 4.x, but I've done jail images of 9 and 10 on 11 and 12 hosts as part of a CI system.The shims you're talking about are not shims at all, just packages of the older libraries that a program built for an older version of FreeBSD would expect. You can go ahead and look at the package manifests if you don't believe me. They're literally just a handful of older shared libraries.
Honestly, I can't remember a time when the syscall table changed in a backwards incompatible manner. The compat packages are only needed if you're trying to run an older program with a newer userland. If you're running an older jail in a newer freebsd host, you can run your program as-is because those libraries have already been installed.
> If the kernel version differs from the one that the system utilities have been built with, for example, a kernel built from -CURRENT sources is installed on a -RELEASE system, many system status commands like ps(1) and vmstat(8) will not work. To fix this, recompile and install a world built with the same version of the source tree as the kernel. It is never a good idea to use a different version of the kernel than the rest of the operating system.
https://web.archive.org/web/20180602150408/https://www.freeb...
It certainly seems like the freebsd userland and kernel are fairly tightly coupled where even basic utilities won't work anymore on a version change.
If you were making a more earnest argument you'd probably have looked at the current version of the documentation and noted that it doesn't have the warning you quoted.
https://docs.freebsd.org/en/books/handbook/kernelconfig/#ker...
Note that FreeBSD 10.0 was released in January 2014, over nine years ago. 10.4, which is the oldest base jail image I have kicking around, was released in 2017. So the userland-kernel interfaces you're wringing your hands over have remained stable for nearly a decade across three or four different major releases.
Of all the concerns I'd have about running FreeBSD and/or jails in a prod environment, dealing with binary compatibility across different major versions is not even on my radar and not even remotely an advantage for docker.
# uname -rv
12.4-RELEASE-p1 FreeBSD 12.4-RELEASE-p1 GENERIC
# ldd /bin/ps
/bin/ps:
libm.so.5 => /lib/libm.so.5 (0x800254000)
libkvm.so.7 => /lib/libkvm.so.7 (0x80028b000)
libjail.so.1 => /lib/libjail.so.1 (0x80029e000)
libxo.so.0 => /lib/libxo.so.0 (0x8002a6000)
libc.so.7 => /lib/libc.so.7 (0x8002c5000)
libelf.so.2 => /lib/libelf.so.2 (0x8006b9000)
libutil.so.9 => /lib/libutil.so.9 (0x8006d4000)
# md5sum /bin/ps
ad8b5c8966c71e31cdc9603967860fa7 /bin/ps
# objdump -p /lib/libc.so.7 | tail -12
Version definitions:
1 0x01 0x0865f4e7 libc.so.7
2 0x00 0x077a28b0 FBSD_1.0
3 0x00 0x077a28b1 FBSD_1.1
4 0x00 0x077a28b2 FBSD_1.2
5 0x00 0x077a28b3 FBSD_1.3
6 0x00 0x077a28b4 FBSD_1.4
7 0x00 0x077a28b5 FBSD_1.5
8 0x00 0x077a28b6 FBSD_1.6
9 0x00 0x0f1efaa0 FBSDprivate_1.0
# iocage create -r 10.4-RELEASE
e950694e-6182-410d-bc70-1a8f6e340516 successfully created!
# iocage start e950694e-6182-410d-bc70-1a8f6e340516
* Starting e950694e-6182-410d-bc70-1a8f6e340516
+ Started OK
+ Using devfs_ruleset: 1007 (iocage generated default)
+ Using IP options: ip4.saddrsel=1 ip4=new ip6.saddrsel=1 ip6=new
+ Starting services OK
+ Executing poststart OK
# iocage console e950694e-6182-410d-bc70-1a8f6e340516
FreeBSD 12.4-RELEASE-p1 GENERIC
Welcome to FreeBSD!
Release Notes, Errata: https://www.FreeBSD.org/releases/
Security Advisories: https://www.FreeBSD.org/security/
FreeBSD Handbook: https://www.FreeBSD.org/handbook/
FreeBSD FAQ: https://www.FreeBSD.org/faq/
Questions List: https://lists.FreeBSD.org/mailman/listinfo/freebsd-questions/
FreeBSD Forums: https://forums.FreeBSD.org/
Documents installed with the system are in the /usr/local/share/doc/freebsd/
directory, or can be installed later with: pkg install en-freebsd-doc
For other languages, replace "en" with a language code like de or fr.
Show the version of FreeBSD installed: freebsd-version ; uname -a
Please include that output and any error messages when posting questions.
Introduction to manual pages: man man
FreeBSD directory layout: man hier
Edit /etc/motd to change this login announcement.
# ldd /bin/ps
/bin/ps:
libm.so.5 => /lib/libm.so.5 (0x800827000)
libkvm.so.6 => /lib/libkvm.so.6 (0x800a50000)
libjail.so.1 => /lib/libjail.so.1 (0x800c59000)
libc.so.7 => /lib/libc.so.7 (0x800e5e000)
# objdump -p /lib/libc.so.7 | tail -16
Version definitions:
1 0x01 0x0865f4e7 libc.so.7
2 0x00 0x077a28b0 FBSD_1.0
3 0x00 0x077a28b1 FBSD_1.1
FBSD_1.0
4 0x00 0x077a28b2 FBSD_1.2
FBSD_1.1
5 0x00 0x077a28b3 FBSD_1.3
FBSD_1.2
6 0x00 0x077a28b4 FBSD_1.4
FBSD_1.3
7 0x00 0x077a28b5 FBSD_1.5
FBSD_1.4
8 0x00 0x0f1efaa0 FBSDprivate_1.0
FBSD_1.5
# md5 /bin/ps
MD5 (/bin/ps) = 8a9c364705d29beb98503415428067cc
# ps
PID TT STAT TIME COMMAND
80454 39 IJ 0:00.01 login [pam] (login)
80455 39 SJ 0:00.03 -csh (csh)
80593 39 R+J 0:00.00 psThat said, I wouldn't look to run FreeBSD in a production environment without a good reason and 13 looks to be where I'll jump ship to Debian for homelab stuff. The big thing holding me back before was ZFS, but that's essentially a non-issue now.
It had everything I needed to start manually setting up jails to my liking.
I eventually had to get some additional help online but you come a long, long, long way with that book in your hand.
This jail allows me to lock things down to minimal access to other services I need remotely, such as an SSH tunnel to Home Assistant.
I run my FreeBSD server mainly for ZFS. Adding a jail for remote access adds to the usefulness that hardware.
Potentially a non-vnet jail with the ipv4/ipv6 options set may also be an option. I used to use jails with those settings to squeeze multiple environments into a single host at Yahoo.
Greetings! Miss the ole days at the ‘Hoo when we were all FBSD based!
ssh { exec.start = "/bin/sh /etc/rc"; exec.stop = "/bin/sh /etc/rc.shutdown"; exec.clean; mount.devfs; path = "/var/jail/ssh"; host.hostname = "ssh"; vnet; vnet.interface += "em0"; }
It's IPv6 only, so this is key in rc.conf: rtsold_enable="YES"
OpenBSD PF based router does the rest. IPv6 simplifies things here.
PF on FreeBSD isn't the most ideal, sure, but I can limit local access on inet6.
For SSH tunnel, it's straight forward.
It's awesome that you can do everything you would want with a jail with only 3 config files: rc.conf (for networking and start-up), pf.conf (for firewalling/routing), and jail.conf (for specifying jail params like mount points, network if setup, etc.).
Super clean, super easy.
- bastille https://bastillebsd.org
- pot https://potluck.honeyguide.net
bastille is great for personal and small setups, pot is aimed at larger scale and meant to be used along with hashicorp nomad+consul
And, you'd be missing out on features like VNET that came later (FreeBSD 8), unless Apple reintegrated with upstream, which is pretty rare for them. (They did update the FreeBSD userland, once)
It does seem like a feature worth porting, though.
Docker does not have this limitation. You can run a container that is based on a newer version of Linux than the host.
FreeBSD is developed as a whole unit. It makes it easier to reason that a 13.2 userland doesn't run on a 12.4 kernel.
FWIW, it would take quite a long time for glibc itself to start requiring Linux 6.3 on its current targets. Since glibc 2.24 (Aug. 2016), the minimum supported kernel has been at most Linux 3.2 (Jan. 2012), on every target that has existed that long. And that's the smallest that the gap between the glibc and Linux releases has ever gotten (except for new targets). Extrapolating, we'd have to wait for glibc 2.47 (Feb. 2028) to require Linux 6.3 (Apr. 2023), if that gap were to be repeated, something which I don't find particularly likely.
That is to say, with the exception of new targets, you'll rarely see a userland that absolutely requires the latest Linux kernel, even possibly if it suggests that kernel for the best support.
For example: Per its own README, systemd requires Linux 3.15 at absolute minimum, recommends Linux 4.15 for baseline functionality to at least work, and specifies Linux 5.7 for full BPF functionality.
(Well. Technically it's kind of true. You can run a container based on a newer kernel, it'll just crash when you use any new features)