Re: rcd(8) - new service manager daemon

Alexander Leidinger <[email protected]> Mon, 15 Jun 2026 15:35:29 +0200
Newsgroups gmane.os.freebsd.devel.hackers
Organization No organization, this is a private message.
Message-ID <[email protected]>
Am 2026-06-15 08:47, schrieb Baptiste Daroussin:

> rcd adds features not in launchd (or beyond what launchd does): native 
> jail(2)
> integration for service isolation (like recent addition to rcng), 
> rctl(2)
> resource control (like rcng), OOM protection via PROC_SPROTECT (like 
> rcng),
> embedded Lua for service hooks, template units for per-instance 
> services
> (dhclient@em0), and JSON Schema validation.

Do I understand this and another reply correctly, that it incorporates 
into the rcd binary the "service jails" functionality which I introduced 
into rcng (<service>_svcj="YES" and <service>_svcj_options), but it is 
not a fully functional containerization environment like docker or 
kubernetes or such?

If I understand this correctly: both thumbs up!

There is a way of per-instance services in the ports tree. One example 
is www/oauth2-proxy (simplest example without much dependencies). As it 
rcd backward compatible I don't worry about the existing ports tree. My 
point here is: Are you aware of it? And as I have not seen the syntax of 
your UCL, do you think it allows similar flexibility? I have similar 
per-instance template support in www/openhab (but this is more complex 
to setup in testing than the oauth2-proxy).

Bye,
Alexander.

-- 
http://www.Leidinger.net [email protected]: PGP 0x8F31830F9F2772BF
http://www.FreeBSD.org    [email protected]  : PGP 0x8F31830F9F2772BF
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEER9UlYXp1PSd08nWXEg2wmwP42IYFAmov/7IACgkQEg2wmwP4
2IbLwg//eO21ZXileqH1nf+coR4B4EUwfWfHuQNJaS1hMLznMeat/2UWWKo0G8oI
7+10madnY+1kQ/2hUkDb1zHkuXAPvZXk9haa36EiLEGbiW1TJct87gX2FwCTCaoj
F65mBz9u96VnaluL19UtOf9FFDthT9QZrSG34guyYsh4YoFRfK5QFunn0LX4g+rV
YDkmI8+TKWP1Y5wiLKJMab5uNs8TFlr8KltP/AtnOxwLWdFazQVrhI6EgMRcCPfS
8yqWXSUfta0TrBtdijm6zLJxUUzFwunoGkCaFGX1a5oua7ADGQoE7vVxBEZdozIq
DQWopLZ0PiN3jX7fO3i9HR2J29YPHkeSC4BzwNRpaVJ3tBtOgPLRWcUzn+mptOo+
xNOlV+8g2zENDbWt5J9lvFgVCvSSkBEhITt8lt+YCNgzQNSEPWlmUXAgsMOlCUwr
qe8xHDbrpZ0nRBfLCu4H4nsU/SgUo6z1w21tWXYBkbPtT0eub4b2gCJwv+3JCcIJ
SNlIJdlcU9ccrUS8Ayt6SGJZkJ1KQB/2FjB5VEq1OxeUDRj6JFL4xg+kBqtqoGgk
tRynSfbPd9sAZ8ulKojvbq3Wu1yC530FiAG5Vn5nfpCIDi+QwnQ4uwsbQwZhoocz
OhhaqnX2W4rX3HEP6xEI98bz3VXBZ9/U1lbF7Q8Q2+rNhkIjTr4=
=W3Sr
-----END PGP SIGNATURE-----