3 lxc: linux Container library
5 (C) Copyright Canonical Ltd. 2013
8 Serge Hallyn <serge.hallyn@ubuntu.com>
10 This library is free software; you can redistribute it and/or
11 modify it under the terms of the GNU Lesser General Public
12 License as published by the Free Software Foundation; either
13 version 2.1 of the License, or (at your option) any later version.
15 This library is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
18 Lesser General Public License for more details.
20 You should have received a copy of the GNU Lesser General Public
21 License along with this library; if not, write to the Free Software
22 Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
26 <!DOCTYPE refentry PUBLIC @docdtd@ [
28 <!ENTITY commonoptions SYSTEM "@builddir@/common_options.sgml">
29 <!ENTITY seealso SYSTEM "@builddir@/see_also.sgml">
34 <docinfo><date>@LXC_GENERATE_DATE@</date></docinfo>
37 <refentrytitle>lxc-user-nic</refentrytitle>
38 <manvolnum>1</manvolnum>
42 <refname>lxc-user-nic</refname>
45 Manage nics in another network namespace
51 <command>lxc-user-nic</command>
52 <command>create</command>
53 <arg choice="req"><replaceable>lxcpath</replaceable></arg>
54 <arg choice="req"><replaceable>name</replaceable></arg>
55 <arg choice="req"><replaceable>pid</replaceable></arg>
56 <arg choice="req"><replaceable>type</replaceable></arg>
57 <arg choice="req"><replaceable>bridge</replaceable></arg>
58 <arg choice="req"><replaceable>container nicname</replaceable></arg>
62 <command>lxc-user-nic</command>
63 <command>delete</command>
64 <arg choice="req"><replaceable>lxcpath</replaceable></arg>
65 <arg choice="req"><replaceable>name</replaceable></arg>
66 <arg choice="req"><replaceable>path to network namespace</replaceable></arg>
67 <arg choice="req"><replaceable>type</replaceable></arg>
68 <arg choice="req"><replaceable>bridge</replaceable></arg>
69 <arg choice="req"><replaceable>container nicname</replaceable></arg>
74 <title>Description</title>
77 <command>lxc-user-nic</command> is a setuid-root program with which
78 unprivileged users may manage network interfaces for use by a
82 It will consult the configuration file <filename>@LXC_USERNIC_CONF@</filename>
83 to determine the number of interfaces which the calling user is allowed to
84 create, and which bridge he may attach them to. It tracks the
85 number of interfaces each user has created using the file
86 <filename>@LXC_USERNIC_DB@</filename>. It ensures that the calling
87 user is privileged over the network namespace to which the interface
89 <command>lxc-user-nic</command> also allows to delete network devices.
90 Currently only ovs ports can be deleted.
97 <title>Options</title>
102 <option><replaceable>lxcpath</replaceable></option>
106 The path of the container. This is currently not used.
113 <option><replaceable>name</replaceable></option>
117 The name of the container. This is currently not used.
124 <option><replaceable>pid</replaceable></option>
128 The process id for the task to whose network namespace the interface
136 <option><replaceable>type</replaceable></option>
140 The network interface type to attach. Currently only veth is
141 supported. With this type, two interfaces representing each
142 tunnel endpoint are created. One endpoint will be attached
143 to the specified bridge, while the other will be passed into
151 <option><replaceable>bridge</replaceable></option>
155 The bridge to which to attach the network interface, for
156 instance <filename>lxcbr0</filename>.
163 <option><replaceable>container nicname</replaceable></option>
167 The desired interface name in the container. This will be
168 <filename>eth0</filename> if unspecified.
175 <option><replaceable>path to network namespace</replaceable></option>
179 A path to open to get a file descriptor for the target
181 This is only relevant when an veth device is deleted.
191 <title>See Also</title>
195 <refentrytitle><command>lxc</command></refentrytitle>
196 <manvolnum>1</manvolnum>
200 <refentrytitle><command>lxc-start</command></refentrytitle>
201 <manvolnum>1</manvolnum>
205 <refentrytitle><command>lxc-usernet</command></refentrytitle>
206 <manvolnum>5</manvolnum>
212 <title>Author</title>
213 <para>Christian Brauner <email>christian@brauner.io</email></para>
214 <para>Serge Hallyn <email>serge@hallyn.com</email></para>
215 <para>Daniel Lezcano <email>daniel.lezcano@free.fr</email></para>
220 <!-- Keep this comment at the end of the file
225 sgml-minimize-attributes:nil
226 sgml-always-quote-attributes:t
229 sgml-parent-document:nil
230 sgml-default-dtd-file:nil
231 sgml-exposed-tags:nil
232 sgml-local-catalogs:nil
233 sgml-local-ecat-files:nil