FreeBSD Containers and Orchestration
FreeBSD introduced its container, OS-level virtualization primitive in 1999 in the form of a security-oriented isolation framework and subsystem called Jails. Similar to OpenVZ Containers in 2005, Solaris Zones, LXC, Docker and other implementations, FreeBSD Jails allow isolation of applications or entire stacks with their own processes, filesystems and users, whilst using the same host operating system kernel.
Contents
Container Tools: Base System
Out of the box, FreeBSD provides:
Container Tools: Third-Party
These third-party tools aim to simplify and speed up the process of creating and managing FreeBSD jail-based containers on individual hosts, and many include additional support and integration for FreeBSD features such as bhyve virtualization, ZFS, Virtual Networks (VNET), Templating, Import/Export among others.
ACTIVE PROJECTS
AppJail
Jail framework written in C and posix shell to create, deploy and maintain jail-based containers.
- First Release: 2022
Latest Release - see GitHub repos below
Tools:
Supports:
- Supervisor (healthcheckers)
Parallel startup (Healthcheckers, jails & NAT).
- ZFS support.
- RACCT/RCTL support.
- NAT support.
- Port forwarding.
- IPv4 and IPv6 support.
- DHCP and SLAAC support.
- Virtual networks.
- Bridge support.
- VNET support.
- Text file to make jails: Makejail.
- Netgraph support.
LinuxJails support.
- Supports thin and thick jails.
TinyJails - Experimental feature to create a very stripped down jail that is very useful to distribute.
- Startup order control.
- Jail dependency support.
InitScript for interactive use of jails.
Commands to import/export jails (ZFS & Tarballs).
Table interface to easily integrate AppJail with scripts.
- Images.
- Dynamic DEVFS ruleset management.
- OCI support - Containers everywhere!
Orchestration with AppJail Director, LittleJet, or Overlord.
Podman, Buildah
A FreeBSD port of the https://github.com/containers stack. Install sysutils/podman-suite from FreeBSD Ports/Packages.
- Suitable for evaluation and non-critical production.
- Implemented using standard FreeBSD jails, using VNET for network isolation.
- Container storage using the zfs and vfs storage drivers. ZFS is strongly preferred since its use of snapshots and clones makes it more efficient than vfs.
- Podman provides a CLI which is a drop-in replacement for Docker. Optionally, Podman also supports managing containers remotely for orchestration.
Supports docker-style networking using a port of https://github.com/containernetworking/plugins. This allows containers to communicate on a private network as well as optionally publishing container ports on the container host to allow external connections to container services.
- Container images use the same OCI formats and infrastructure as containerd and can be shared between the two implementations.
- If the Linux emulator is enabled on the host, Podman can run Linux container images which don't depend on Linux features which are not yet emulated.
runj / containerd / nerdctl
Experimental FreeBSD Jail execution runtime implementation and FreeBSD OCI specification development.
Latest Releases - see respective GutHub repos below
- nerdctl provides a Docker-compatible CLI for containerd
Supports:
containerd See also Samual Karp's blog
- Linux Jail support
Network Support (Experimental)
Bastille
Command-line (shell) tool and automation framework for jail-based containers.
- Latest Release: 2025 (0.14.2025*)
Supports:
- FreeBSD Features: ZFS, VNET
- Other Features: Template Creation, Import, Export
- Has a container / template registry
pot
- Latest Release: Jul 2024 (0.16.1)
Command-line (shell) tool for jail-based containers.
Supports:
- FreeBSD Features: ZFS, pf, rctl.
Orchestration with HashiCorp Nomad, See pot homepage, sysutils/nomad and sysutils/nomad-pot-driver)>>
cbsd
Command-line and TUI (shell) tool for jail-based containers.
- Last Release: 2025 (14.2.6)
Supports:
FreeBSD Features: ZFS, VNET, bhyve, Xen
- Other Features: Templates and Profiles
None of the above orchestration tools have a "run a plain vanilla linux inside the container" feature, but the start/stop/templating feature of them does not prevent a manually created plain-vanilla-linux-jail.
LEGACY PROJECTS
iocage
Command-line (Python, originally shell) tool for jail-based containers.
- First Release: ~2016 (need citation)
- Latest Release: 2019 (1.2)
Supports:
- FreeBSD Features: ZFS (required), VNET
- Other Features: Template Creation, Import, Export
ioc
Re-implementation (Python) of iocage.
- First Release: Unknown, but ~2017 (need citation)
- Latest Release: 2019 (0.8.2)
iocell
Fork of original (shell) iocage
- First Release: ~2016 ("v2.0.0") (need citation)
- Latest Release: 2017 (2.1.2)
ezjail
Command-line (shell) tool for jail-based containers.
- Latest Release: 2015 (3.4.2)
Supports:
- FreeBSD Features: ZFS, VNET (via manual scripting)
- Other Features: Template Creation, Import, Export
Container Stores
Daemonless
Native container platform for FreeBSD. Run 90+ modern apps with standard OCI tooling.
AppJail Makejails
Centralized repository to find and deploy useful Makejails
Both of the above stores use dbuild as the primary build engine. It provides a unified interface for building, testing, and publishing FreeBSD OCI container images, ensuring consistency between local development and CI/CD environments.
Container Orchestration
The container tools above can be used as a base for multi-host orchestration, by exporting containers from one host, and either moving the container to another host, or by utilising shared storage (eg: SAN) or ZFS to switch container datasets from one host to another and importing it on the target host.
Additionally the following FreeBSD container orchestration tools are available:
HashiCorp Nomad (jail-task driver)
Working Groups
FreeBSD Cloud Native Containers Technologies
If you are interested in helping to improve the support for cloud native containers on FreeBSD, please come to the FreeBSD Cloud Native Containers Technologies meeting. You will work with experienced FreeBSD users and committers in a congenial environment and play a role adding some of the most important enterprise capabilities.
The (draft) goal of the group is "Identify and make progress on important work needed to make FreeBSD a top-tier choice for running cloud native containerised workloads. Aim to champion these pieces of work to the point where they can "graduate" from this group e.g. have an owner and are being actively worked on." Active areas of work (see links below) include Podman, Kubernetes, Container Registry, and more.
Learn about current feature status:
Completed or Mostly Completed Work
Work in Progress and Needs
FreeBSD OCI Containers aims to build for FreeBSD a comprehensive base of high-demand application container images, the same building blocks that underpin most container-based platform and software development across Linux and macOS.
Need someone to port Netavark to FreeBSD. Netavark is required for Podman 6.0 and later and replaces the system of CNI plugins that the FreeBSD port uses for Podman 5.x
- * UPDATE August 11, 2026 - It looks as though someone will be doing this work! As this is finalized, we will update the meeting notes and/or this wiki with details.
Biweekly Meeting Details
The 45 minute meeting is biweekly on Mondays at 16:30 UTC time (NOTE: this time will follow UK daylight savings time, so will go forward an hour in the spring).
You can find this meeting, and many others, on the FreeBSD Community Calendar and easily add them to your own calendar.
Joining instructions
https://zoom.us/j/98902292435?pwd=Fbgso5jzdHMb5EIF5VvP12hLCX752N.1
Meeting ID: 989 0229 2435 Passcode: 759073