If I set this up i would just run every service on the same machine sans jails. Are there any practical benefits to doing it like this? The extra complexity buys some slight measure of security in case one service is exploited, I guess?
They're somewhat similar to how you'd use Docker containers on Linux, but have different approach to security and networking.