]> git.proxmox.com Git - mirror_lxc.git/blame - config/templates/archlinux.userns.conf.in
Prevent write_config from corrupting container config
[mirror_lxc.git] / config / templates / archlinux.userns.conf.in
CommitLineData
c194ffc1
AV
1# Based on fedora.userns.conf.in
2# CAP_SYS_ADMIN in init-user-ns is required for cgroup.devices
3lxc.cgroup.devices.deny =
4lxc.cgroup.devices.allow =
5
6# We can't move bind-mounts, so don't use /dev/lxc/
7lxc.devttydir =
8
9# Extra bind-mounts for userns
10lxc.mount.entry = /dev/console dev/console none bind,create=file 0 0
11lxc.mount.entry = /dev/full dev/full none bind,create=file 0 0
12lxc.mount.entry = /dev/null dev/null none bind,create=file 0 0
13lxc.mount.entry = /dev/random dev/random none bind,create=file 0 0
14lxc.mount.entry = /dev/tty dev/tty none bind,create=file 0 0
15lxc.mount.entry = /dev/urandom dev/urandom none bind,create=file 0 0
16lxc.mount.entry = /dev/zero dev/zero none bind,create=file 0 0
17
18# Extra fstab entries as mountall can't mount those by itself
19# lxc.mount.entry = /sys/firmware/efi/efivars sys/firmware/efi/efivars none bind,optional 0 0
20lxc.mount.entry = /proc/sys/fs/binfmt_misc proc/sys/fs/binfmt_misc none bind,optional 0 0