]> git.proxmox.com Git - mirror_lxc.git/commitdiff
nesting: remove the nesting hint from configuration templates
authorSerge Hallyn <serge.hallyn@ubuntu.com>
Tue, 15 Mar 2016 21:47:44 +0000 (14:47 -0700)
committerSerge Hallyn <serge.hallyn@ubuntu.com>
Tue, 15 Mar 2016 21:47:44 +0000 (14:47 -0700)
we're having it inserted in every config by the lxcapi_create
itself.

Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
config/templates/debian.common.conf.in
config/templates/ubuntu.common.conf.in
templates/lxc-cirros.in

index e034b954cded25ca7cbf56d3681dc486c1b42fb4..07c2bc8b19264cd024df0f5044ad1c13cbd6fa5e 100644 (file)
@@ -9,10 +9,6 @@ lxc.devttydir =
 # (uncommented) to the container's configuration file.
 #lxc.aa_profile = unconfined
 
-# To support container nesting on an Ubuntu host while retaining most of
-# apparmor's added security, use the following line instead.
-#lxc.aa_profile = lxc-container-default-with-nesting
-
 # If you wish to allow mounting block filesystems, then use the following
 # line instead, and make sure to grant access to the block device and/or loop
 # devices below in lxc.cgroup.devices.allow.
index 7e171de84e3ee8263b2b91894fcdefc4c896a97f..a1c60d244588bd9b55e337b8f5377979ab8593df 100644 (file)
@@ -12,10 +12,6 @@ lxc.mount.entry = mqueue dev/mqueue mqueue rw,relatime,create=dir,optional 0 0
 # (uncommented) to the container's configuration file.
 #lxc.aa_profile = unconfined
 
-# To support container nesting on an Ubuntu host while retaining most of
-# apparmor's added security, use the following line instead.
-#lxc.aa_profile = lxc-container-default-with-nesting
-
 # Uncomment the following line to autodetect squid-deb-proxy configuration on the
 # host and forward it to the guest at start time.
 #lxc.hook.pre-start = /usr/share/lxc/hooks/squid-deb-proxy-client
index 55fc257c2a2bbace2a5af089592b98740ea9b714..395416ba2a30cfca184892ef67147d3390d7bb8c 100644 (file)
@@ -130,8 +130,6 @@ lxc.cap.drop = sys_module mac_admin mac_override sys_time
 
 # When using LXC with apparmor, uncomment the next line to run unconfined:
 #lxc.aa_profile = unconfined
-# To support container nesting on an Ubuntu host, uncomment next two lines:
-#lxc.aa_profile = lxc-container-default-with-nesting
 lxc.mount.auto = cgroup:mixed proc:mixed sys:mixed
 
 lxc.cgroup.devices.deny = a