mirror of
https://git.proxmox.com/git/mirror_lxc
synced 2025-07-27 09:48:32 +00:00

Those aren't supported, it's just a lucky coincidence that they weren't causing problems. Signed-off-by: Stéphane Graber <stgraber@ubuntu.com> Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
49 lines
1.2 KiB
Plaintext
49 lines
1.2 KiB
Plaintext
# Default configuration shared by all containers
|
|
|
|
# Setup the LXC devices in /dev/lxc/
|
|
lxc.devttydir = lxc
|
|
|
|
# Allow for 1024 pseudo terminals
|
|
lxc.pts = 1024
|
|
|
|
# Setup 4 tty devices
|
|
lxc.tty = 4
|
|
|
|
# Drop some harmful capabilities
|
|
lxc.cap.drop = mac_admin mac_override sys_time sys_module
|
|
|
|
# Set the pivot directory
|
|
lxc.pivotdir = lxc_putold
|
|
|
|
# Ensure hostname is changed on clone
|
|
lxc.hook.clone = @LXCHOOKDIR@/clonehostname
|
|
|
|
# CGroup whitelist
|
|
lxc.cgroup.devices.deny = a
|
|
## Allow any mknod (but not reading/writing the node)
|
|
lxc.cgroup.devices.allow = c *:* m
|
|
lxc.cgroup.devices.allow = b *:* m
|
|
## Allow specific devices
|
|
### /dev/null
|
|
lxc.cgroup.devices.allow = c 1:3 rwm
|
|
### /dev/zero
|
|
lxc.cgroup.devices.allow = c 1:5 rwm
|
|
### /dev/full
|
|
lxc.cgroup.devices.allow = c 1:7 rwm
|
|
### /dev/tty
|
|
lxc.cgroup.devices.allow = c 5:0 rwm
|
|
### /dev/console
|
|
lxc.cgroup.devices.allow = c 5:1 rwm
|
|
### /dev/ptmx
|
|
lxc.cgroup.devices.allow = c 5:2 rwm
|
|
### /dev/random
|
|
lxc.cgroup.devices.allow = c 1:8 rwm
|
|
### /dev/urandom
|
|
lxc.cgroup.devices.allow = c 1:9 rwm
|
|
### /dev/pts/*
|
|
lxc.cgroup.devices.allow = c 136:* rwm
|
|
|
|
# Blacklist some syscalls which are not safe in privileged
|
|
# containers
|
|
lxc.seccomp = @LXCTEMPLATECONFIG@/common.seccomp
|