]> git.proxmox.com Git - lxc.git/blame - config/openwrt.common.conf.in
bump version to 3.1.0-65
[lxc.git] / config / openwrt.common.conf.in
CommitLineData
f49c89ac
WB
1# Default console settings
2lxc.tty.dir = lxc
3lxc.tty.max = 4
4lxc.pty.max = 1024
5
6# Default capabilities
7lxc.cap.drop = mac_admin
8lxc.cap.drop = mac_override
9lxc.cap.drop = sys_admin
10lxc.cap.drop = sys_module
11lxc.cap.drop = sys_nice
12lxc.cap.drop = sys_pacct
13lxc.cap.drop = sys_ptrace
14lxc.cap.drop = sys_rawio
15lxc.cap.drop = sys_resource
16lxc.cap.drop = sys_time
17lxc.cap.drop = sys_tty_config
18lxc.cap.drop = syslog
19lxc.cap.drop = wake_alarm
20
21# Default cgroups - all denied except those whitelisted
22lxc.cgroup.devices.deny = a
23## /dev/null and zero
24lxc.cgroup.devices.allow = c 1:3 rwm
25lxc.cgroup.devices.allow = c 1:5 rwm
26## consoles
27lxc.cgroup.devices.allow = c 5:0 rwm
28lxc.cgroup.devices.allow = c 5:1 rwm
29## /dev/{,u}random
30lxc.cgroup.devices.allow = c 1:8 rwm
31lxc.cgroup.devices.allow = c 1:9 rwm
32## /dev/pts/*
33lxc.cgroup.devices.allow = c 5:2 rwm
34lxc.cgroup.devices.allow = c 136:* rwm
35## rtc
36lxc.cgroup.devices.allow = c 254:0 rm
37## tun
38lxc.cgroup.devices.allow = c 10:200 rwm
39## dev/tty0
40lxc.cgroup.devices.allow = c 4:0 rwm
41## dev/tty1
42lxc.cgroup.devices.allow = c 4:1 rwm
43
44## To use loop devices, copy the following line to the container's
45## configuration file (uncommented).
46#lxc.cgroup.devices.allow = b 7:* rwm
47
48# Blacklist some syscalls which are not safe in privileged
49# containers
50lxc.seccomp.profile = /usr/share/lxc/config/common.seccomp