Open source · FreeBSD · BSD-3-Clause

Hardened, automated containers on FreeBSD.

BastilleBSD builds the tools to deploy and manage secure, jailed applications — and the configuration management to automate the hosts they run on.

Latest 1.4.4 pkg install bastille Runs on FreeBSD 14+
Why Bastille

Security and automation, built in

Everything you need to run production containers on FreeBSD — nothing you don't.

Hardened by Default

Proactive security and hardened container environments from the moment of installation — not an afterthought.

Read-Only Root

Confine the root user and prevent unauthorized modifications to the container base.

Stackable Templates

Compose complex deployments from modular, reusable Bastillefile templates — like Dockerfiles for jails.

Secure Networking

Flexible loopback, bridged, and VNET networking with pf firewall integration and strong isolation.

Target Any Container

Run a command across one, many, or all containers with a single, consistent syntax.

Snapshots & Backups

ZFS-backed snapshots and exports make container state management and recovery effortless.

Zero Dependencies

Bastille is lightweight POSIX shell. Containers are efficient — and so is the tool that manages them.

Resource Limits

Fine-grained CPU, memory, and disk quotas per container via rctl — prevent noisy-neighbor contention.

Built on FreeBSD Jails

Leverage the industry-standard containerization primitive, battle-tested in production for two decades.

Runs anywhere FreeBSD does

Laptop & Desktop

Bare-Metal Servers

Raspberry Pi / ARM

Cloud & VPS

Professional Services

Expert help, straight from the source

Work directly with the creator of BastilleBSD to design, harden, and operate your FreeBSD infrastructure — or train your team to do it.

Ready when you are

Deploy your first container in 20 minutes

Follow the getting-started guide, or reach out about consulting and training for your team.