FYI, we just merged FreeBSD jail support into the OCI runtime spec v1.3[1]. There is already at least one implementation of it[2] as well.

[1]: https://github.com/opencontainers/runtime-spec/pull/1286 [2]: https://github.com/samuelkarp/runj