// the find
BastilleBSD/bastille
Bastille is an open-source system for automating deployment and management of containerized applications on FreeBSD.
Bastille automates FreeBSD jail creation and management — think Docker-ish workflow but built on jails and ZFS instead of cgroups/namespaces. It's for FreeBSD admins who want repeatable, templated jail deployment without hand-rolling jail.conf files.
It's a thin shell wrapper around native FreeBSD primitives (jail, ZFS, jib) rather than reinventing them, so there's no separate runtime or daemon to trust. CI runs shellcheck and has a real unit-test suite with dozens of per-subcommand Bastillefile fixtures across ZFS and UFS, which is more test discipline than most shell projects bother with. Networking support is genuinely deep — VNET, VLAN, bridged and cloned interfaces, NAT, rdr — covering cases Docker networking doesn't touch cleanly. Packaged in the official FreeBSD ports tree, so install/upgrade goes through the normal OS package flow instead of curl-pipe-bash.
It's ~10k+ lines of POSIX shell for something that's effectively a container orchestrator; that's a maintenance ceiling shellcheck doesn't fully cover — logic bugs and edge cases in string-based state handling are easy to introduce and hard to test exhaustively. The 1.0 epair renaming migration (manual jail restarts, MAC address changes on VNET jails without -M) shows the networking layer has had breaking, disruptive changes that hit existing deployments. It's single-host only — no clustering, no remote orchestration, so it doesn't scale past 'jails on one box' without external tooling. And it's FreeBSD-exclusive by definition, so the addressable audience is small and the docs/community are correspondingly thin compared to Docker or even other jail managers like iocage.