FreeCORE Home Install Demo Documentation

Bastille Jails

Configure the Bastille service in the web interface, then create and manage jails with the bastille command; the interface shows each jail's state and resource use.

FreeCORE 15.1 includes Bastille alongside the existing iocage jail manager. The two engines keep separate releases, configuration and lifecycle, and existing iocage jails are not converted. See Plugins, Jails and Applications when choosing where a workload should run.

From 15.1-RC3 the web interface is a console over Bastille rather than a second jail manager. It configures the Bastille service and shows every jail with its state and resource use; the jails themselves are created and managed on the console with the bastille command. Open Jails, then the cogwheel, then Bastille Jails. The cogwheel on that page leads to Bastille Settings and back to iocage Jails.

Configure the Service

  1. Open Bastille Settings from the cogwheel and select a healthy, online, unlocked Data Pool. Bastille keeps its releases, jails, templates and logs below /mnt/<pool>/bastille.
  2. Review Startup Delay (seconds) and Parallel Start Limit, which control automatic startup, then click Save.
  3. To start jails after a host boot, enable Start Automatically for Bastille on Services, and mark each jail for startup as shown below. The configured pool must be available when startup runs.
Bastille data pool and startup settings in FreeCORE 15.1
Bastille Settings before initial configuration.

Once a pool is configured, bastille finds it on its own. No environment variable and no per-shell setup is needed; open a console as root and use the commands below. Changing the selected pool later is not a jail migration procedure.

Download a Release

A release is the FreeBSD base a jail runs on. Its version need not match the FreeCORE version. Download it as packages (-p), so that it can be updated later:

bastille bootstrap -p 15.1-RELEASE
bastille list release

FreeCORE does not ship freebsd-update, so a release fetched as a single archive (bastille bootstrap 15.1-RELEASE, without -p) cannot receive security patches on this system. A packaged release is updated through pkg, and this works for FreeBSD 15.0 and later.

Keep a Release Updated

bastille update 15.1-RELEASE

Every jail built on the release shares its userland; restart those jails afterwards. bastille update <jail> applies only to thick jails.

Create a Jail

A VNET jail has its own network stack and can use DHCP. Bastille attaches it to a bridge on the interface you name, creating the bridge when needed:

bastille create -V web 15.1-RELEASE DHCP vtnet0

For a static address, give the address and prefix instead of DHCP:

bastille create -V web 15.1-RELEASE 192.168.1.50/24 vtnet0

Without -V the jail shares the host's network stack and needs a static address, which is added as an alias on the interface. DHCP requires a VNET jail, as it does with iocage. Names use 1–11 letters or digits; Bastille's own command names are reserved.

A host interface belongs to one bridge. -V places the interface you name in a bridge of its own; iocage's VNET jails use bridge0 on the interface they are given. Do not point both at the same interface: whichever starts second cannot attach. On a host that also runs iocage VNET jails, give Bastille a different interface.

Start, Stop and Inspect

bastille start web
bastille stop web
bastille restart web
bastille list all
bastille console web

To include a jail in automatic startup, set its boot flag; the service's Start Automatically setting must also be enabled:

bastille config web set boot on

The web interface shows the same state. Use Refresh on Bastille Jails after changing a jail on the console.

Apply a Template

A Bastille template is a directory with a Bastillefile that installs and configures an application inside a jail. Templates come from git repositories you choose, fetched with the same bootstrap command as a release:

bastille bootstrap https://github.com/tschettervictor/bsd-apps
bastille template web bsd-apps/jellyfin

A template runs commands inside the jail as root, so choose repositories the way you choose packages, and read a template before applying it to a customized jail. A failed template can leave partial changes; inspect the jail before retrying. FreeCORE reviews none of the templates a repository provides.

What Not to Do

Do not run bastille setup. It configures a plain FreeBSD host: it writes a firewall ruleset that FreeCORE's Bastille service refuses to start with, and its other changes land in files FreeCORE regenerates at every boot. The web interface configures the storage; the image provides the rest.

bastille limits needs the loader tunable kern.racct.enable=1. Add it in System → Tunables (type loader) and reboot, as for iocage resource limits.

FreeCORE does not configure PF for Bastille, and Bastille refuses bastille rdr for VNET jails. A VNET jail has its own address on your network, so services in it are reached directly; templates that declare RDR lines do not apply here.

Reclaim Space

bastille destroy web
bastille destroy 15.1-RELEASE

Destroying a release is refused while a jail still uses it. Datasets mounted into a jail from elsewhere on the pool are not part of the jail and remain.

What the Web Interface Shows

Bastille Jails lists every jail by name: State, IPv4 (the leased address of a running DHCP jail, shown with its interface as vnet0|…, or DHCP while it is stopped), Release, Auto-start, and, for running jails, live CPU, Memory and Processes, plus the jail's Disk usage. Console Log shows a jail's console output. Releases lists each downloaded release with its size and the jails using it. The Guests card on the dashboard shows running Bastille jails in their own section; a row opens Bastille Jails. See Bastille Screens for every field.