]> git.proxmox.com Git - pve-docs.git/blame - pct.conf.5-opts.adoc
Precise certificate generation
[pve-docs.git] / pct.conf.5-opts.adoc
CommitLineData
4d47f125 1`arch`: `<amd64 | arm64 | armhf | i386>` ('default =' `amd64`)::
71e16346
DM
2
3OS architecture type.
4
013dc89f 5`cmode`: `<console | shell | tty>` ('default =' `tty`)::
71e16346 6
c2993fe5 7Console mode. By default, the console command tries to open a connection to one of the available tty devices. By setting cmode to 'console' it tries to attach to /dev/console instead. If you set cmode to 'shell', it simply invokes a shell inside the container (no login).
71e16346 8
013dc89f 9`console`: `<boolean>` ('default =' `1`)::
71e16346
DM
10
11Attach a console device (/dev/console) to the container.
12
013dc89f 13`cores`: `<integer> (1 - 128)` ::
de0983cb
DM
14
15The number of cores assigned to the container. A container can use all available cores by default.
16
013dc89f 17`cpulimit`: `<number> (0 - 128)` ('default =' `0`)::
71e16346
DM
18
19Limit of CPU usage.
20+
c2993fe5 21NOTE: If the computer has 2 CPUs, it has a total of '2' CPU time. Value '0' indicates no CPU limit.
71e16346 22
013dc89f 23`cpuunits`: `<integer> (0 - 500000)` ('default =' `1024`)::
71e16346 24
c2993fe5 25CPU weight for a VM. Argument is used in the kernel fair scheduler. The larger the number is, the more CPU time this VM gets. Number is relative to the weights of all the other running VMs.
71e16346
DM
26+
27NOTE: You can disable fair-scheduler configuration by setting this to 0.
28
013dc89f 29`description`: `<string>` ::
71e16346
DM
30
31Container description. Only used on the configuration web interface.
32
e2d681b3 33`features`: `[fuse=<1|0>] [,keyctl=<1|0>] [,mount=<fstype;fstype;...>] [,nesting=<1|0>]` ::
4d47f125
TL
34
35Allow containers access to advanced features.
36
e2d681b3
TL
37`fuse`=`<boolean>` ('default =' `0`);;
38
39Allow using 'fuse' file systems in a container. Note that interactions between fuse and the freezer cgroup can potentially cause I/O deadlocks.
40
4d47f125
TL
41`keyctl`=`<boolean>` ('default =' `0`);;
42
43For unprivileged containers only: Allow the use of the keyctl() system call. This is required to use docker inside a container. By default unprivileged containers will see this system call as non-existent. This is mostly a workaround for systemd-networkd, as it will treat it as a fatal error when some keyctl() operations are denied by the kernel due to lacking permissions. Essentially, you can choose between running systemd-networkd or docker.
44
45`mount`=`<fstype;fstype;...>` ;;
46
47Allow mounting file systems of specific types. This should be a list of file system types as used with the mount command. Note that this can have negative effects on the container's security. With access to a loop device, mounting a file can circumvent the mknod permission of the devices cgroup, mounting an NFS file system can block the host's I/O completely and prevent it from rebooting, etc.
48
49`nesting`=`<boolean>` ('default =' `0`);;
50
51Allow nesting. Best used with unprivileged containers with additional id mapping. Note that this will expose procfs and sysfs contents of the host to the guest.
52
013dc89f 53`hostname`: `<string>` ::
71e16346
DM
54
55Set a host name for the container.
56
4d47f125 57`lock`: `<backup | disk | migrate | mounted | rollback | snapshot | snapshot-delete>` ::
71e16346
DM
58
59Lock/unlock the VM.
60
013dc89f 61`memory`: `<integer> (16 - N)` ('default =' `512`)::
71e16346
DM
62
63Amount of RAM for the VM in MB.
64
5d9c884c 65`mp[n]`: `[volume=]<volume> ,mp=<Path> [,acl=<1|0>] [,backup=<1|0>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346 66
c2993fe5
DM
67Use volume as container mount point.
68
013dc89f 69`acl`=`<boolean>` ;;
c2993fe5
DM
70
71Explicitly enable or disable ACL support.
72
013dc89f 73`backup`=`<boolean>` ;;
c2993fe5 74
de0983cb 75Whether to include the mount point in backups (only used for volume mount points).
c2993fe5
DM
76
77`mp`=`<Path>` ;;
78
de0983cb 79Path to the mount point as seen from inside the container.
2c0dde61
DM
80+
81NOTE: Must not contain any symlinks for security reasons.
c2993fe5 82
013dc89f 83`quota`=`<boolean>` ;;
c2993fe5
DM
84
85Enable user quotas inside the container (not supported with zfs subvolumes)
86
5d9c884c
DM
87`replicate`=`<boolean>` ('default =' `1`);;
88
89Will include this volume to a storage replica job.
90
013dc89f 91`ro`=`<boolean>` ;;
c2993fe5 92
de0983cb
DM
93Read-only mount point
94
013dc89f 95`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
96
97Mark this non-volume mount point as available on all nodes.
98+
99WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
100
101`size`=`<DiskSize>` ;;
102
103Volume size (read only value).
104
105`volume`=`<volume>` ;;
106
107Volume, device or directory to mount into the container.
71e16346 108
013dc89f 109`nameserver`: `<string>` ::
71e16346 110
c2993fe5 111Sets DNS server IP address for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346 112
2489d6df 113`net[n]`: `name=<string> [,bridge=<bridge>] [,firewall=<1|0>] [,gw=<GatewayIPv4>] [,gw6=<GatewayIPv6>] [,hwaddr=<XX:XX:XX:XX:XX:XX>] [,ip=<(IPv4/CIDR|dhcp|manual)>] [,ip6=<(IPv6/CIDR|auto|dhcp|manual)>] [,mtu=<integer>] [,rate=<mbps>] [,tag=<integer>] [,trunks=<vlanid[;vlanid...]>] [,type=<veth>]` ::
71e16346
DM
114
115Specifies network interfaces for the container.
116
c2993fe5
DM
117`bridge`=`<bridge>` ;;
118
119Bridge to attach the network device to.
120
013dc89f 121`firewall`=`<boolean>` ;;
c2993fe5
DM
122
123Controls whether this interface's firewall rules should be used.
124
125`gw`=`<GatewayIPv4>` ;;
126
127Default gateway for IPv4 traffic.
128
129`gw6`=`<GatewayIPv6>` ;;
130
131Default gateway for IPv6 traffic.
132
133`hwaddr`=`<XX:XX:XX:XX:XX:XX>` ;;
134
135The interface MAC address. This is dynamically allocated by default, but you can set that statically if needed, for example to always have the same link-local IPv6 address. (lxc.network.hwaddr)
136
2489d6df 137`ip`=`<(IPv4/CIDR|dhcp|manual)>` ;;
c2993fe5
DM
138
139IPv4 address in CIDR format.
140
2489d6df 141`ip6`=`<(IPv6/CIDR|auto|dhcp|manual)>` ;;
c2993fe5
DM
142
143IPv6 address in CIDR format.
144
013dc89f 145`mtu`=`<integer> (64 - N)` ;;
c2993fe5
DM
146
147Maximum transfer unit of the interface. (lxc.network.mtu)
148
149`name`=`<string>` ;;
150
151Name of the network device as seen from inside the container. (lxc.network.name)
152
153`rate`=`<mbps>` ;;
154
155Apply rate limiting to the interface
156
013dc89f 157`tag`=`<integer> (1 - 4094)` ;;
c2993fe5
DM
158
159VLAN tag for this interface.
160
161`trunks`=`<vlanid[;vlanid...]>` ;;
162
163VLAN ids to pass through the interface
164
013dc89f 165`type`=`<veth>` ;;
c2993fe5
DM
166
167Network interface type.
168
013dc89f 169`onboot`: `<boolean>` ('default =' `0`)::
71e16346
DM
170
171Specifies whether a VM will be started during system bootup.
172
013dc89f 173`ostype`: `<alpine | archlinux | centos | debian | fedora | gentoo | opensuse | ubuntu | unmanaged>` ::
71e16346 174
c2993fe5 175OS type. This is used to setup configuration inside the container, and corresponds to lxc setup scripts in /usr/share/lxc/config/<ostype>.common.conf. Value 'unmanaged' can be used to skip and OS specific setup.
71e16346 176
013dc89f 177`protection`: `<boolean>` ('default =' `0`)::
71e16346 178
c2993fe5 179Sets the protection flag of the container. This will prevent the CT or CT's disk remove/update operation.
71e16346 180
5d9c884c 181`rootfs`: `[volume=]<volume> [,acl=<1|0>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346
DM
182
183Use volume as container root.
184
013dc89f 185`acl`=`<boolean>` ;;
c2993fe5
DM
186
187Explicitly enable or disable ACL support.
188
013dc89f 189`quota`=`<boolean>` ;;
c2993fe5
DM
190
191Enable user quotas inside the container (not supported with zfs subvolumes)
192
5d9c884c
DM
193`replicate`=`<boolean>` ('default =' `1`);;
194
195Will include this volume to a storage replica job.
196
013dc89f 197`ro`=`<boolean>` ;;
c2993fe5 198
de0983cb
DM
199Read-only mount point
200
013dc89f 201`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
202
203Mark this non-volume mount point as available on all nodes.
204+
205WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
206
207`size`=`<DiskSize>` ;;
208
209Volume size (read only value).
210
211`volume`=`<volume>` ;;
212
213Volume, device or directory to mount into the container.
214
013dc89f 215`searchdomain`: `<string>` ::
71e16346 216
c2993fe5 217Sets DNS search domains for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346
DM
218
219`startup`: `[[order=]\d+] [,up=\d+] [,down=\d+] ` ::
220
c2993fe5 221Startup and shutdown behavior. Order is a non-negative number defining the general startup order. Shutdown in done with reverse ordering. Additionally you can set the 'up' or 'down' delay in seconds, which specifies a delay to wait before the next VM is started or stopped.
71e16346 222
013dc89f 223`swap`: `<integer> (0 - N)` ('default =' `512`)::
71e16346
DM
224
225Amount of SWAP for the VM in MB.
226
013dc89f 227`template`: `<boolean>` ('default =' `0`)::
71e16346
DM
228
229Enable/disable Template.
230
013dc89f 231`tty`: `<integer> (0 - 6)` ('default =' `2`)::
71e16346
DM
232
233Specify the number of tty available to the container
234
013dc89f 235`unprivileged`: `<boolean>` ('default =' `0`)::
71e16346 236
c2993fe5 237Makes the container run as unprivileged user. (Should not be modified manually.)
71e16346 238
013dc89f 239`unused[n]`: `<string>` ::
71e16346 240
c2993fe5 241Reference to unused volumes. This is used internally, and should not be modified manually.
71e16346 242