]> git.proxmox.com Git - pve-docs.git/blame - pct.conf.5-opts.adoc
vzdump: add section about backup fleecing
[pve-docs.git] / pct.conf.5-opts.adoc
CommitLineData
9d2e98ed 1`arch`: `<amd64 | arm64 | armhf | i386 | riscv32 | riscv64>` ('default =' `amd64`)::
71e16346
DM
2
3OS architecture type.
4
013dc89f 5`cmode`: `<console | shell | tty>` ('default =' `tty`)::
71e16346 6
c2993fe5 7Console mode. By default, the console command tries to open a connection to one of the available tty devices. By setting cmode to 'console' it tries to attach to /dev/console instead. If you set cmode to 'shell', it simply invokes a shell inside the container (no login).
71e16346 8
013dc89f 9`console`: `<boolean>` ('default =' `1`)::
71e16346
DM
10
11Attach a console device (/dev/console) to the container.
12
4772952b 13`cores`: `<integer> (1 - 8192)` ::
de0983cb
DM
14
15The number of cores assigned to the container. A container can use all available cores by default.
16
4772952b 17`cpulimit`: `<number> (0 - 8192)` ('default =' `0`)::
71e16346
DM
18
19Limit of CPU usage.
20+
c2993fe5 21NOTE: If the computer has 2 CPUs, it has a total of '2' CPU time. Value '0' indicates no CPU limit.
71e16346 22
4e7f60c2 23`cpuunits`: `<integer> (0 - 500000)` ('default =' `cgroup v1: 1024, cgroup v2: 100`)::
71e16346 24
4e7f60c2 25CPU weight for a container. Argument is used in the kernel fair scheduler. The larger the number is, the more CPU time this container gets. Number is relative to the weights of all the other running guests.
71e16346 26
739d4d64
TL
27`debug`: `<boolean>` ('default =' `0`)::
28
29Try to be more verbose. For now this only enables debug log-level on start.
30
013dc89f 31`description`: `<string>` ::
71e16346 32
8f4d9c87 33Description for the Container. Shown in the web-interface CT's summary. This is saved as comment inside the configuration file.
71e16346 34
fa22697b
TL
35`dev[n]`: `[[path=]<Path>] [,gid=<integer>] [,mode=<Octal access mode>] [,uid=<integer>]` ::
36
37Device to pass through to the container
38
39`gid`=`<integer> (0 - N)` ;;
40
41Group ID to be assigned to the device node
42
43`mode`=`<Octal access mode>` ;;
44
45Access mode to be set on the device node
46
47`path`=`<Path>` ;;
48
49Path to the device to pass through to the container
50
51`uid`=`<integer> (0 - N)` ;;
52
53User ID to be assigned to the device node
54
c5aa7e14 55`features`: `[force_rw_sys=<1|0>] [,fuse=<1|0>] [,keyctl=<1|0>] [,mknod=<1|0>] [,mount=<fstype;fstype;...>] [,nesting=<1|0>]` ::
4d47f125
TL
56
57Allow containers access to advanced features.
58
c5aa7e14
TL
59`force_rw_sys`=`<boolean>` ('default =' `0`);;
60
61Mount /sys in unprivileged containers as `rw` instead of `mixed`. This can break networking under newer (>= v245) systemd-network use.
62
e2d681b3
TL
63`fuse`=`<boolean>` ('default =' `0`);;
64
65Allow using 'fuse' file systems in a container. Note that interactions between fuse and the freezer cgroup can potentially cause I/O deadlocks.
66
4d47f125
TL
67`keyctl`=`<boolean>` ('default =' `0`);;
68
69For unprivileged containers only: Allow the use of the keyctl() system call. This is required to use docker inside a container. By default unprivileged containers will see this system call as non-existent. This is mostly a workaround for systemd-networkd, as it will treat it as a fatal error when some keyctl() operations are denied by the kernel due to lacking permissions. Essentially, you can choose between running systemd-networkd or docker.
70
c5aa7e14
TL
71`mknod`=`<boolean>` ('default =' `0`);;
72
73Allow unprivileged containers to use mknod() to add certain device nodes. This requires a kernel with seccomp trap to user space support (5.3 or newer). This is experimental.
74
4d47f125
TL
75`mount`=`<fstype;fstype;...>` ;;
76
77Allow mounting file systems of specific types. This should be a list of file system types as used with the mount command. Note that this can have negative effects on the container's security. With access to a loop device, mounting a file can circumvent the mknod permission of the devices cgroup, mounting an NFS file system can block the host's I/O completely and prevent it from rebooting, etc.
78
79`nesting`=`<boolean>` ('default =' `0`);;
80
81Allow nesting. Best used with unprivileged containers with additional id mapping. Note that this will expose procfs and sysfs contents of the host to the guest.
82
5f26e15b
TL
83`hookscript`: `<string>` ::
84
85Script that will be exectued during various steps in the containers lifetime.
86
013dc89f 87`hostname`: `<string>` ::
71e16346
DM
88
89Set a host name for the container.
90
1c532546 91`lock`: `<backup | create | destroyed | disk | fstrim | migrate | mounted | rollback | snapshot | snapshot-delete>` ::
71e16346 92
4e7f60c2 93Lock/unlock the container.
71e16346 94
013dc89f 95`memory`: `<integer> (16 - N)` ('default =' `512`)::
71e16346 96
4e7f60c2 97Amount of RAM for the container in MB.
71e16346 98
7cbed89a 99`mp[n]`: `[volume=]<volume> ,mp=<Path> [,acl=<1|0>] [,backup=<1|0>] [,mountoptions=<opt[;opt...]>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346 100
d2656385 101Use volume as container mount point. Use the special syntax STORAGE_ID:SIZE_IN_GiB to allocate a new volume.
c2993fe5 102
013dc89f 103`acl`=`<boolean>` ;;
c2993fe5
DM
104
105Explicitly enable or disable ACL support.
106
013dc89f 107`backup`=`<boolean>` ;;
c2993fe5 108
de0983cb 109Whether to include the mount point in backups (only used for volume mount points).
c2993fe5 110
7cbed89a
TL
111`mountoptions`=`<opt[;opt...]>` ;;
112
113Extra mount options for rootfs/mps.
114
c2993fe5
DM
115`mp`=`<Path>` ;;
116
de0983cb 117Path to the mount point as seen from inside the container.
2c0dde61
DM
118+
119NOTE: Must not contain any symlinks for security reasons.
c2993fe5 120
013dc89f 121`quota`=`<boolean>` ;;
c2993fe5
DM
122
123Enable user quotas inside the container (not supported with zfs subvolumes)
124
5d9c884c
DM
125`replicate`=`<boolean>` ('default =' `1`);;
126
127Will include this volume to a storage replica job.
128
013dc89f 129`ro`=`<boolean>` ;;
c2993fe5 130
de0983cb
DM
131Read-only mount point
132
013dc89f 133`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
134
135Mark this non-volume mount point as available on all nodes.
136+
137WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
138
139`size`=`<DiskSize>` ;;
140
141Volume size (read only value).
142
143`volume`=`<volume>` ;;
144
145Volume, device or directory to mount into the container.
71e16346 146
013dc89f 147`nameserver`: `<string>` ::
71e16346 148
c2993fe5 149Sets DNS server IP address for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346 150
9d2e98ed 151`net[n]`: `name=<string> [,bridge=<bridge>] [,firewall=<1|0>] [,gw=<GatewayIPv4>] [,gw6=<GatewayIPv6>] [,hwaddr=<XX:XX:XX:XX:XX:XX>] [,ip=<(IPv4/CIDR|dhcp|manual)>] [,ip6=<(IPv6/CIDR|auto|dhcp|manual)>] [,link_down=<1|0>] [,mtu=<integer>] [,rate=<mbps>] [,tag=<integer>] [,trunks=<vlanid[;vlanid...]>] [,type=<veth>]` ::
71e16346
DM
152
153Specifies network interfaces for the container.
154
c2993fe5
DM
155`bridge`=`<bridge>` ;;
156
157Bridge to attach the network device to.
158
013dc89f 159`firewall`=`<boolean>` ;;
c2993fe5
DM
160
161Controls whether this interface's firewall rules should be used.
162
163`gw`=`<GatewayIPv4>` ;;
164
165Default gateway for IPv4 traffic.
166
167`gw6`=`<GatewayIPv6>` ;;
168
169Default gateway for IPv6 traffic.
170
171`hwaddr`=`<XX:XX:XX:XX:XX:XX>` ;;
172
95895385 173A common MAC address with the I/G (Individual/Group) bit not set.
c2993fe5 174
2489d6df 175`ip`=`<(IPv4/CIDR|dhcp|manual)>` ;;
c2993fe5
DM
176
177IPv4 address in CIDR format.
178
2489d6df 179`ip6`=`<(IPv6/CIDR|auto|dhcp|manual)>` ;;
c2993fe5
DM
180
181IPv6 address in CIDR format.
182
9d2e98ed
TL
183`link_down`=`<boolean>` ;;
184
185Whether this interface should be disconnected (like pulling the plug).
186
81a3384d 187`mtu`=`<integer> (64 - 65535)` ;;
c2993fe5
DM
188
189Maximum transfer unit of the interface. (lxc.network.mtu)
190
191`name`=`<string>` ;;
192
193Name of the network device as seen from inside the container. (lxc.network.name)
194
195`rate`=`<mbps>` ;;
196
197Apply rate limiting to the interface
198
013dc89f 199`tag`=`<integer> (1 - 4094)` ;;
c2993fe5
DM
200
201VLAN tag for this interface.
202
203`trunks`=`<vlanid[;vlanid...]>` ;;
204
205VLAN ids to pass through the interface
206
013dc89f 207`type`=`<veth>` ;;
c2993fe5
DM
208
209Network interface type.
210
013dc89f 211`onboot`: `<boolean>` ('default =' `0`)::
71e16346 212
4e7f60c2 213Specifies whether a container will be started during system bootup.
71e16346 214
7af2edf9 215`ostype`: `<alpine | archlinux | centos | debian | devuan | fedora | gentoo | nixos | opensuse | ubuntu | unmanaged>` ::
71e16346 216
c2993fe5 217OS type. This is used to setup configuration inside the container, and corresponds to lxc setup scripts in /usr/share/lxc/config/<ostype>.common.conf. Value 'unmanaged' can be used to skip and OS specific setup.
71e16346 218
013dc89f 219`protection`: `<boolean>` ('default =' `0`)::
71e16346 220
c2993fe5 221Sets the protection flag of the container. This will prevent the CT or CT's disk remove/update operation.
71e16346 222
7cbed89a 223`rootfs`: `[volume=]<volume> [,acl=<1|0>] [,mountoptions=<opt[;opt...]>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346
DM
224
225Use volume as container root.
226
013dc89f 227`acl`=`<boolean>` ;;
c2993fe5
DM
228
229Explicitly enable or disable ACL support.
230
7cbed89a
TL
231`mountoptions`=`<opt[;opt...]>` ;;
232
233Extra mount options for rootfs/mps.
234
013dc89f 235`quota`=`<boolean>` ;;
c2993fe5
DM
236
237Enable user quotas inside the container (not supported with zfs subvolumes)
238
5d9c884c
DM
239`replicate`=`<boolean>` ('default =' `1`);;
240
241Will include this volume to a storage replica job.
242
013dc89f 243`ro`=`<boolean>` ;;
c2993fe5 244
de0983cb
DM
245Read-only mount point
246
013dc89f 247`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
248
249Mark this non-volume mount point as available on all nodes.
250+
251WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
252
253`size`=`<DiskSize>` ;;
254
255Volume size (read only value).
256
257`volume`=`<volume>` ;;
258
259Volume, device or directory to mount into the container.
260
013dc89f 261`searchdomain`: `<string>` ::
71e16346 262
c2993fe5 263Sets DNS search domains for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346
DM
264
265`startup`: `[[order=]\d+] [,up=\d+] [,down=\d+] ` ::
266
c2993fe5 267Startup and shutdown behavior. Order is a non-negative number defining the general startup order. Shutdown in done with reverse ordering. Additionally you can set the 'up' or 'down' delay in seconds, which specifies a delay to wait before the next VM is started or stopped.
71e16346 268
013dc89f 269`swap`: `<integer> (0 - N)` ('default =' `512`)::
71e16346 270
4e7f60c2 271Amount of SWAP for the container in MB.
71e16346 272
5c1699e5
TL
273`tags`: `<string>` ::
274
275Tags of the Container. This is only meta information.
276
013dc89f 277`template`: `<boolean>` ('default =' `0`)::
71e16346
DM
278
279Enable/disable Template.
280
04d22a9f
TL
281`timezone`: `<string>` ::
282
283Time zone to use in the container. If option isn't set, then nothing will be done. Can be set to 'host' to match the host time zone, or an arbitrary time zone option from /usr/share/zoneinfo/zone.tab
284
013dc89f 285`tty`: `<integer> (0 - 6)` ('default =' `2`)::
71e16346
DM
286
287Specify the number of tty available to the container
288
013dc89f 289`unprivileged`: `<boolean>` ('default =' `0`)::
71e16346 290
c2993fe5 291Makes the container run as unprivileged user. (Should not be modified manually.)
71e16346 292
c5aa7e14 293`unused[n]`: `[volume=]<volume>` ::
71e16346 294
c2993fe5 295Reference to unused volumes. This is used internally, and should not be modified manually.
71e16346 296
c5aa7e14
TL
297`volume`=`<volume>` ;;
298
299The volume that is not used currently.
300