]> git.proxmox.com Git - pve-docs.git/blame - pct.conf.5-opts.adoc
backup: clarify that CLI means FS-level and highlight retention-note
[pve-docs.git] / pct.conf.5-opts.adoc
CommitLineData
4d47f125 1`arch`: `<amd64 | arm64 | armhf | i386>` ('default =' `amd64`)::
71e16346
DM
2
3OS architecture type.
4
013dc89f 5`cmode`: `<console | shell | tty>` ('default =' `tty`)::
71e16346 6
c2993fe5 7Console mode. By default, the console command tries to open a connection to one of the available tty devices. By setting cmode to 'console' it tries to attach to /dev/console instead. If you set cmode to 'shell', it simply invokes a shell inside the container (no login).
71e16346 8
013dc89f 9`console`: `<boolean>` ('default =' `1`)::
71e16346
DM
10
11Attach a console device (/dev/console) to the container.
12
4772952b 13`cores`: `<integer> (1 - 8192)` ::
de0983cb
DM
14
15The number of cores assigned to the container. A container can use all available cores by default.
16
4772952b 17`cpulimit`: `<number> (0 - 8192)` ('default =' `0`)::
71e16346
DM
18
19Limit of CPU usage.
20+
c2993fe5 21NOTE: If the computer has 2 CPUs, it has a total of '2' CPU time. Value '0' indicates no CPU limit.
71e16346 22
013dc89f 23`cpuunits`: `<integer> (0 - 500000)` ('default =' `1024`)::
71e16346 24
c2993fe5 25CPU weight for a VM. Argument is used in the kernel fair scheduler. The larger the number is, the more CPU time this VM gets. Number is relative to the weights of all the other running VMs.
71e16346
DM
26+
27NOTE: You can disable fair-scheduler configuration by setting this to 0.
28
739d4d64
TL
29`debug`: `<boolean>` ('default =' `0`)::
30
31Try to be more verbose. For now this only enables debug log-level on start.
32
013dc89f 33`description`: `<string>` ::
71e16346 34
8f4d9c87 35Description for the Container. Shown in the web-interface CT's summary. This is saved as comment inside the configuration file.
71e16346 36
c5aa7e14 37`features`: `[force_rw_sys=<1|0>] [,fuse=<1|0>] [,keyctl=<1|0>] [,mknod=<1|0>] [,mount=<fstype;fstype;...>] [,nesting=<1|0>]` ::
4d47f125
TL
38
39Allow containers access to advanced features.
40
c5aa7e14
TL
41`force_rw_sys`=`<boolean>` ('default =' `0`);;
42
43Mount /sys in unprivileged containers as `rw` instead of `mixed`. This can break networking under newer (>= v245) systemd-network use.
44
e2d681b3
TL
45`fuse`=`<boolean>` ('default =' `0`);;
46
47Allow using 'fuse' file systems in a container. Note that interactions between fuse and the freezer cgroup can potentially cause I/O deadlocks.
48
4d47f125
TL
49`keyctl`=`<boolean>` ('default =' `0`);;
50
51For unprivileged containers only: Allow the use of the keyctl() system call. This is required to use docker inside a container. By default unprivileged containers will see this system call as non-existent. This is mostly a workaround for systemd-networkd, as it will treat it as a fatal error when some keyctl() operations are denied by the kernel due to lacking permissions. Essentially, you can choose between running systemd-networkd or docker.
52
c5aa7e14
TL
53`mknod`=`<boolean>` ('default =' `0`);;
54
55Allow unprivileged containers to use mknod() to add certain device nodes. This requires a kernel with seccomp trap to user space support (5.3 or newer). This is experimental.
56
4d47f125
TL
57`mount`=`<fstype;fstype;...>` ;;
58
59Allow mounting file systems of specific types. This should be a list of file system types as used with the mount command. Note that this can have negative effects on the container's security. With access to a loop device, mounting a file can circumvent the mknod permission of the devices cgroup, mounting an NFS file system can block the host's I/O completely and prevent it from rebooting, etc.
60
61`nesting`=`<boolean>` ('default =' `0`);;
62
63Allow nesting. Best used with unprivileged containers with additional id mapping. Note that this will expose procfs and sysfs contents of the host to the guest.
64
5f26e15b
TL
65`hookscript`: `<string>` ::
66
67Script that will be exectued during various steps in the containers lifetime.
68
013dc89f 69`hostname`: `<string>` ::
71e16346
DM
70
71Set a host name for the container.
72
1c532546 73`lock`: `<backup | create | destroyed | disk | fstrim | migrate | mounted | rollback | snapshot | snapshot-delete>` ::
71e16346
DM
74
75Lock/unlock the VM.
76
013dc89f 77`memory`: `<integer> (16 - N)` ('default =' `512`)::
71e16346
DM
78
79Amount of RAM for the VM in MB.
80
7cbed89a 81`mp[n]`: `[volume=]<volume> ,mp=<Path> [,acl=<1|0>] [,backup=<1|0>] [,mountoptions=<opt[;opt...]>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346 82
d2656385 83Use volume as container mount point. Use the special syntax STORAGE_ID:SIZE_IN_GiB to allocate a new volume.
c2993fe5 84
013dc89f 85`acl`=`<boolean>` ;;
c2993fe5
DM
86
87Explicitly enable or disable ACL support.
88
013dc89f 89`backup`=`<boolean>` ;;
c2993fe5 90
de0983cb 91Whether to include the mount point in backups (only used for volume mount points).
c2993fe5 92
7cbed89a
TL
93`mountoptions`=`<opt[;opt...]>` ;;
94
95Extra mount options for rootfs/mps.
96
c2993fe5
DM
97`mp`=`<Path>` ;;
98
de0983cb 99Path to the mount point as seen from inside the container.
2c0dde61
DM
100+
101NOTE: Must not contain any symlinks for security reasons.
c2993fe5 102
013dc89f 103`quota`=`<boolean>` ;;
c2993fe5
DM
104
105Enable user quotas inside the container (not supported with zfs subvolumes)
106
5d9c884c
DM
107`replicate`=`<boolean>` ('default =' `1`);;
108
109Will include this volume to a storage replica job.
110
013dc89f 111`ro`=`<boolean>` ;;
c2993fe5 112
de0983cb
DM
113Read-only mount point
114
013dc89f 115`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
116
117Mark this non-volume mount point as available on all nodes.
118+
119WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
120
121`size`=`<DiskSize>` ;;
122
123Volume size (read only value).
124
125`volume`=`<volume>` ;;
126
127Volume, device or directory to mount into the container.
71e16346 128
013dc89f 129`nameserver`: `<string>` ::
71e16346 130
c2993fe5 131Sets DNS server IP address for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346 132
2489d6df 133`net[n]`: `name=<string> [,bridge=<bridge>] [,firewall=<1|0>] [,gw=<GatewayIPv4>] [,gw6=<GatewayIPv6>] [,hwaddr=<XX:XX:XX:XX:XX:XX>] [,ip=<(IPv4/CIDR|dhcp|manual)>] [,ip6=<(IPv6/CIDR|auto|dhcp|manual)>] [,mtu=<integer>] [,rate=<mbps>] [,tag=<integer>] [,trunks=<vlanid[;vlanid...]>] [,type=<veth>]` ::
71e16346
DM
134
135Specifies network interfaces for the container.
136
c2993fe5
DM
137`bridge`=`<bridge>` ;;
138
139Bridge to attach the network device to.
140
013dc89f 141`firewall`=`<boolean>` ;;
c2993fe5
DM
142
143Controls whether this interface's firewall rules should be used.
144
145`gw`=`<GatewayIPv4>` ;;
146
147Default gateway for IPv4 traffic.
148
149`gw6`=`<GatewayIPv6>` ;;
150
151Default gateway for IPv6 traffic.
152
153`hwaddr`=`<XX:XX:XX:XX:XX:XX>` ;;
154
95895385 155A common MAC address with the I/G (Individual/Group) bit not set.
c2993fe5 156
2489d6df 157`ip`=`<(IPv4/CIDR|dhcp|manual)>` ;;
c2993fe5
DM
158
159IPv4 address in CIDR format.
160
2489d6df 161`ip6`=`<(IPv6/CIDR|auto|dhcp|manual)>` ;;
c2993fe5
DM
162
163IPv6 address in CIDR format.
164
013dc89f 165`mtu`=`<integer> (64 - N)` ;;
c2993fe5
DM
166
167Maximum transfer unit of the interface. (lxc.network.mtu)
168
169`name`=`<string>` ;;
170
171Name of the network device as seen from inside the container. (lxc.network.name)
172
173`rate`=`<mbps>` ;;
174
175Apply rate limiting to the interface
176
013dc89f 177`tag`=`<integer> (1 - 4094)` ;;
c2993fe5
DM
178
179VLAN tag for this interface.
180
181`trunks`=`<vlanid[;vlanid...]>` ;;
182
183VLAN ids to pass through the interface
184
013dc89f 185`type`=`<veth>` ;;
c2993fe5
DM
186
187Network interface type.
188
013dc89f 189`onboot`: `<boolean>` ('default =' `0`)::
71e16346
DM
190
191Specifies whether a VM will be started during system bootup.
192
d2656385 193`ostype`: `<alpine | archlinux | centos | debian | devuan | fedora | gentoo | opensuse | ubuntu | unmanaged>` ::
71e16346 194
c2993fe5 195OS type. This is used to setup configuration inside the container, and corresponds to lxc setup scripts in /usr/share/lxc/config/<ostype>.common.conf. Value 'unmanaged' can be used to skip and OS specific setup.
71e16346 196
013dc89f 197`protection`: `<boolean>` ('default =' `0`)::
71e16346 198
c2993fe5 199Sets the protection flag of the container. This will prevent the CT or CT's disk remove/update operation.
71e16346 200
7cbed89a 201`rootfs`: `[volume=]<volume> [,acl=<1|0>] [,mountoptions=<opt[;opt...]>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346
DM
202
203Use volume as container root.
204
013dc89f 205`acl`=`<boolean>` ;;
c2993fe5
DM
206
207Explicitly enable or disable ACL support.
208
7cbed89a
TL
209`mountoptions`=`<opt[;opt...]>` ;;
210
211Extra mount options for rootfs/mps.
212
013dc89f 213`quota`=`<boolean>` ;;
c2993fe5
DM
214
215Enable user quotas inside the container (not supported with zfs subvolumes)
216
5d9c884c
DM
217`replicate`=`<boolean>` ('default =' `1`);;
218
219Will include this volume to a storage replica job.
220
013dc89f 221`ro`=`<boolean>` ;;
c2993fe5 222
de0983cb
DM
223Read-only mount point
224
013dc89f 225`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
226
227Mark this non-volume mount point as available on all nodes.
228+
229WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
230
231`size`=`<DiskSize>` ;;
232
233Volume size (read only value).
234
235`volume`=`<volume>` ;;
236
237Volume, device or directory to mount into the container.
238
013dc89f 239`searchdomain`: `<string>` ::
71e16346 240
c2993fe5 241Sets DNS search domains for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346
DM
242
243`startup`: `[[order=]\d+] [,up=\d+] [,down=\d+] ` ::
244
c2993fe5 245Startup and shutdown behavior. Order is a non-negative number defining the general startup order. Shutdown in done with reverse ordering. Additionally you can set the 'up' or 'down' delay in seconds, which specifies a delay to wait before the next VM is started or stopped.
71e16346 246
013dc89f 247`swap`: `<integer> (0 - N)` ('default =' `512`)::
71e16346
DM
248
249Amount of SWAP for the VM in MB.
250
5c1699e5
TL
251`tags`: `<string>` ::
252
253Tags of the Container. This is only meta information.
254
013dc89f 255`template`: `<boolean>` ('default =' `0`)::
71e16346
DM
256
257Enable/disable Template.
258
04d22a9f
TL
259`timezone`: `<string>` ::
260
261Time zone to use in the container. If option isn't set, then nothing will be done. Can be set to 'host' to match the host time zone, or an arbitrary time zone option from /usr/share/zoneinfo/zone.tab
262
013dc89f 263`tty`: `<integer> (0 - 6)` ('default =' `2`)::
71e16346
DM
264
265Specify the number of tty available to the container
266
013dc89f 267`unprivileged`: `<boolean>` ('default =' `0`)::
71e16346 268
c2993fe5 269Makes the container run as unprivileged user. (Should not be modified manually.)
71e16346 270
c5aa7e14 271`unused[n]`: `[volume=]<volume>` ::
71e16346 272
c2993fe5 273Reference to unused volumes. This is used internally, and should not be modified manually.
71e16346 274
c5aa7e14
TL
275`volume`=`<volume>` ;;
276
277The volume that is not used currently.
278