A jail reads a log; a container's output went to a file of the runtime's own under a path that changes on recreate, so no jail could read a container's service. logging: journald runs the container with the journal as its driver, named in the spec so moving it recreates it; any other place is refused.