1 `arch`: `<amd64 | arm64 | armhf | i386>` ('default =' `amd64`)::
5 `cmode`: `<console | shell | tty>` ('default =' `tty`)::
7 Console mode. By default, the console command tries to open a connection to one of the available tty devices. By setting cmode to 'console' it tries to attach to /dev/console instead. If you set cmode to 'shell', it simply invokes a shell inside the container (no login).
9 `console`: `<boolean>` ('default =' `1`)::
11 Attach a console device (/dev/console) to the container.
13 `cores`: `<integer> (1 - 128)` ::
15 The number of cores assigned to the container. A container can use all available cores by default.
17 `cpulimit`: `<number> (0 - 128)` ('default =' `0`)::
21 NOTE: If the computer has 2 CPUs, it has a total of '2' CPU time. Value '0' indicates no CPU limit.
23 `cpuunits`: `<integer> (0 - 500000)` ('default =' `1024`)::
25 CPU weight for a VM. Argument is used in the kernel fair scheduler. The larger the number is, the more CPU time this VM gets. Number is relative to the weights of all the other running VMs.
27 NOTE: You can disable fair-scheduler configuration by setting this to 0.
29 `description`: `<string>` ::
31 Container description. Only used on the configuration web interface.
33 `features`: `[fuse=<1|0>] [,keyctl=<1|0>] [,mount=<fstype;fstype;...>] [,nesting=<1|0>]` ::
35 Allow containers access to advanced features.
37 `fuse`=`<boolean>` ('default =' `0`);;
39 Allow using 'fuse' file systems in a container. Note that interactions between fuse and the freezer cgroup can potentially cause I/O deadlocks.
41 `keyctl`=`<boolean>` ('default =' `0`);;
43 For unprivileged containers only: Allow the use of the keyctl() system call. This is required to use docker inside a container. By default unprivileged containers will see this system call as non-existent. This is mostly a workaround for systemd-networkd, as it will treat it as a fatal error when some keyctl() operations are denied by the kernel due to lacking permissions. Essentially, you can choose between running systemd-networkd or docker.
45 `mount`=`<fstype;fstype;...>` ;;
47 Allow mounting file systems of specific types. This should be a list of file system types as used with the mount command. Note that this can have negative effects on the container's security. With access to a loop device, mounting a file can circumvent the mknod permission of the devices cgroup, mounting an NFS file system can block the host's I/O completely and prevent it from rebooting, etc.
49 `nesting`=`<boolean>` ('default =' `0`);;
51 Allow nesting. Best used with unprivileged containers with additional id mapping. Note that this will expose procfs and sysfs contents of the host to the guest.
53 `hookscript`: `<string>` ::
55 Script that will be exectued during various steps in the containers lifetime.
57 `hostname`: `<string>` ::
59 Set a host name for the container.
61 `lock`: `<backup | disk | migrate | mounted | rollback | snapshot | snapshot-delete>` ::
65 `memory`: `<integer> (16 - N)` ('default =' `512`)::
67 Amount of RAM for the VM in MB.
69 `mp[n]`: `[volume=]<volume> ,mp=<Path> [,acl=<1|0>] [,backup=<1|0>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71 Use volume as container mount point.
75 Explicitly enable or disable ACL support.
77 `backup`=`<boolean>` ;;
79 Whether to include the mount point in backups (only used for volume mount points).
83 Path to the mount point as seen from inside the container.
85 NOTE: Must not contain any symlinks for security reasons.
87 `quota`=`<boolean>` ;;
89 Enable user quotas inside the container (not supported with zfs subvolumes)
91 `replicate`=`<boolean>` ('default =' `1`);;
93 Will include this volume to a storage replica job.
99 `shared`=`<boolean>` ('default =' `0`);;
101 Mark this non-volume mount point as available on all nodes.
103 WARNING: This option does not share the mount point automatically, it assumes it is shared already!
105 `size`=`<DiskSize>` ;;
107 Volume size (read only value).
109 `volume`=`<volume>` ;;
111 Volume, device or directory to mount into the container.
113 `nameserver`: `<string>` ::
115 Sets DNS server IP address for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
117 `net[n]`: `name=<string> [,bridge=<bridge>] [,firewall=<1|0>] [,gw=<GatewayIPv4>] [,gw6=<GatewayIPv6>] [,hwaddr=<XX:XX:XX:XX:XX:XX>] [,ip=<(IPv4/CIDR|dhcp|manual)>] [,ip6=<(IPv6/CIDR|auto|dhcp|manual)>] [,mtu=<integer>] [,rate=<mbps>] [,tag=<integer>] [,trunks=<vlanid[;vlanid...]>] [,type=<veth>]` ::
119 Specifies network interfaces for the container.
121 `bridge`=`<bridge>` ;;
123 Bridge to attach the network device to.
125 `firewall`=`<boolean>` ;;
127 Controls whether this interface's firewall rules should be used.
129 `gw`=`<GatewayIPv4>` ;;
131 Default gateway for IPv4 traffic.
133 `gw6`=`<GatewayIPv6>` ;;
135 Default gateway for IPv6 traffic.
137 `hwaddr`=`<XX:XX:XX:XX:XX:XX>` ;;
139 The interface MAC address. This is dynamically allocated by default, but you can set that statically if needed, for example to always have the same link-local IPv6 address. (lxc.network.hwaddr)
141 `ip`=`<(IPv4/CIDR|dhcp|manual)>` ;;
143 IPv4 address in CIDR format.
145 `ip6`=`<(IPv6/CIDR|auto|dhcp|manual)>` ;;
147 IPv6 address in CIDR format.
149 `mtu`=`<integer> (64 - N)` ;;
151 Maximum transfer unit of the interface. (lxc.network.mtu)
155 Name of the network device as seen from inside the container. (lxc.network.name)
159 Apply rate limiting to the interface
161 `tag`=`<integer> (1 - 4094)` ;;
163 VLAN tag for this interface.
165 `trunks`=`<vlanid[;vlanid...]>` ;;
167 VLAN ids to pass through the interface
171 Network interface type.
173 `onboot`: `<boolean>` ('default =' `0`)::
175 Specifies whether a VM will be started during system bootup.
177 `ostype`: `<alpine | archlinux | centos | debian | fedora | gentoo | opensuse | ubuntu | unmanaged>` ::
179 OS type. This is used to setup configuration inside the container, and corresponds to lxc setup scripts in /usr/share/lxc/config/<ostype>.common.conf. Value 'unmanaged' can be used to skip and OS specific setup.
181 `protection`: `<boolean>` ('default =' `0`)::
183 Sets the protection flag of the container. This will prevent the CT or CT's disk remove/update operation.
185 `rootfs`: `[volume=]<volume> [,acl=<1|0>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
187 Use volume as container root.
191 Explicitly enable or disable ACL support.
193 `quota`=`<boolean>` ;;
195 Enable user quotas inside the container (not supported with zfs subvolumes)
197 `replicate`=`<boolean>` ('default =' `1`);;
199 Will include this volume to a storage replica job.
203 Read-only mount point
205 `shared`=`<boolean>` ('default =' `0`);;
207 Mark this non-volume mount point as available on all nodes.
209 WARNING: This option does not share the mount point automatically, it assumes it is shared already!
211 `size`=`<DiskSize>` ;;
213 Volume size (read only value).
215 `volume`=`<volume>` ;;
217 Volume, device or directory to mount into the container.
219 `searchdomain`: `<string>` ::
221 Sets DNS search domains for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
223 `startup`: `[[order=]\d+] [,up=\d+] [,down=\d+] ` ::
225 Startup and shutdown behavior. Order is a non-negative number defining the general startup order. Shutdown in done with reverse ordering. Additionally you can set the 'up' or 'down' delay in seconds, which specifies a delay to wait before the next VM is started or stopped.
227 `swap`: `<integer> (0 - N)` ('default =' `512`)::
229 Amount of SWAP for the VM in MB.
231 `template`: `<boolean>` ('default =' `0`)::
233 Enable/disable Template.
235 `tty`: `<integer> (0 - 6)` ('default =' `2`)::
237 Specify the number of tty available to the container
239 `unprivileged`: `<boolean>` ('default =' `0`)::
241 Makes the container run as unprivileged user. (Should not be modified manually.)
243 `unused[n]`: `<string>` ::
245 Reference to unused volumes. This is used internally, and should not be modified manually.