]> git.proxmox.com Git - pve-docs.git/blame - pct.conf.5-opts.adoc
apitoken: use CAUTION for token-only-once-visible note
[pve-docs.git] / pct.conf.5-opts.adoc
CommitLineData
4d47f125 1`arch`: `<amd64 | arm64 | armhf | i386>` ('default =' `amd64`)::
71e16346
DM
2
3OS architecture type.
4
013dc89f 5`cmode`: `<console | shell | tty>` ('default =' `tty`)::
71e16346 6
c2993fe5 7Console mode. By default, the console command tries to open a connection to one of the available tty devices. By setting cmode to 'console' it tries to attach to /dev/console instead. If you set cmode to 'shell', it simply invokes a shell inside the container (no login).
71e16346 8
013dc89f 9`console`: `<boolean>` ('default =' `1`)::
71e16346
DM
10
11Attach a console device (/dev/console) to the container.
12
013dc89f 13`cores`: `<integer> (1 - 128)` ::
de0983cb
DM
14
15The number of cores assigned to the container. A container can use all available cores by default.
16
013dc89f 17`cpulimit`: `<number> (0 - 128)` ('default =' `0`)::
71e16346
DM
18
19Limit of CPU usage.
20+
c2993fe5 21NOTE: If the computer has 2 CPUs, it has a total of '2' CPU time. Value '0' indicates no CPU limit.
71e16346 22
013dc89f 23`cpuunits`: `<integer> (0 - 500000)` ('default =' `1024`)::
71e16346 24
c2993fe5 25CPU weight for a VM. Argument is used in the kernel fair scheduler. The larger the number is, the more CPU time this VM gets. Number is relative to the weights of all the other running VMs.
71e16346
DM
26+
27NOTE: You can disable fair-scheduler configuration by setting this to 0.
28
013dc89f 29`description`: `<string>` ::
71e16346
DM
30
31Container description. Only used on the configuration web interface.
32
e2d681b3 33`features`: `[fuse=<1|0>] [,keyctl=<1|0>] [,mount=<fstype;fstype;...>] [,nesting=<1|0>]` ::
4d47f125
TL
34
35Allow containers access to advanced features.
36
e2d681b3
TL
37`fuse`=`<boolean>` ('default =' `0`);;
38
39Allow using 'fuse' file systems in a container. Note that interactions between fuse and the freezer cgroup can potentially cause I/O deadlocks.
40
4d47f125
TL
41`keyctl`=`<boolean>` ('default =' `0`);;
42
43For unprivileged containers only: Allow the use of the keyctl() system call. This is required to use docker inside a container. By default unprivileged containers will see this system call as non-existent. This is mostly a workaround for systemd-networkd, as it will treat it as a fatal error when some keyctl() operations are denied by the kernel due to lacking permissions. Essentially, you can choose between running systemd-networkd or docker.
44
45`mount`=`<fstype;fstype;...>` ;;
46
47Allow mounting file systems of specific types. This should be a list of file system types as used with the mount command. Note that this can have negative effects on the container's security. With access to a loop device, mounting a file can circumvent the mknod permission of the devices cgroup, mounting an NFS file system can block the host's I/O completely and prevent it from rebooting, etc.
48
49`nesting`=`<boolean>` ('default =' `0`);;
50
51Allow nesting. Best used with unprivileged containers with additional id mapping. Note that this will expose procfs and sysfs contents of the host to the guest.
52
5f26e15b
TL
53`hookscript`: `<string>` ::
54
55Script that will be exectued during various steps in the containers lifetime.
56
013dc89f 57`hostname`: `<string>` ::
71e16346
DM
58
59Set a host name for the container.
60
1c532546 61`lock`: `<backup | create | destroyed | disk | fstrim | migrate | mounted | rollback | snapshot | snapshot-delete>` ::
71e16346
DM
62
63Lock/unlock the VM.
64
013dc89f 65`memory`: `<integer> (16 - N)` ('default =' `512`)::
71e16346
DM
66
67Amount of RAM for the VM in MB.
68
7cbed89a 69`mp[n]`: `[volume=]<volume> ,mp=<Path> [,acl=<1|0>] [,backup=<1|0>] [,mountoptions=<opt[;opt...]>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346 70
c2993fe5
DM
71Use volume as container mount point.
72
013dc89f 73`acl`=`<boolean>` ;;
c2993fe5
DM
74
75Explicitly enable or disable ACL support.
76
013dc89f 77`backup`=`<boolean>` ;;
c2993fe5 78
de0983cb 79Whether to include the mount point in backups (only used for volume mount points).
c2993fe5 80
7cbed89a
TL
81`mountoptions`=`<opt[;opt...]>` ;;
82
83Extra mount options for rootfs/mps.
84
c2993fe5
DM
85`mp`=`<Path>` ;;
86
de0983cb 87Path to the mount point as seen from inside the container.
2c0dde61
DM
88+
89NOTE: Must not contain any symlinks for security reasons.
c2993fe5 90
013dc89f 91`quota`=`<boolean>` ;;
c2993fe5
DM
92
93Enable user quotas inside the container (not supported with zfs subvolumes)
94
5d9c884c
DM
95`replicate`=`<boolean>` ('default =' `1`);;
96
97Will include this volume to a storage replica job.
98
013dc89f 99`ro`=`<boolean>` ;;
c2993fe5 100
de0983cb
DM
101Read-only mount point
102
013dc89f 103`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
104
105Mark this non-volume mount point as available on all nodes.
106+
107WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
108
109`size`=`<DiskSize>` ;;
110
111Volume size (read only value).
112
113`volume`=`<volume>` ;;
114
115Volume, device or directory to mount into the container.
71e16346 116
013dc89f 117`nameserver`: `<string>` ::
71e16346 118
c2993fe5 119Sets DNS server IP address for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346 120
2489d6df 121`net[n]`: `name=<string> [,bridge=<bridge>] [,firewall=<1|0>] [,gw=<GatewayIPv4>] [,gw6=<GatewayIPv6>] [,hwaddr=<XX:XX:XX:XX:XX:XX>] [,ip=<(IPv4/CIDR|dhcp|manual)>] [,ip6=<(IPv6/CIDR|auto|dhcp|manual)>] [,mtu=<integer>] [,rate=<mbps>] [,tag=<integer>] [,trunks=<vlanid[;vlanid...]>] [,type=<veth>]` ::
71e16346
DM
122
123Specifies network interfaces for the container.
124
c2993fe5
DM
125`bridge`=`<bridge>` ;;
126
127Bridge to attach the network device to.
128
013dc89f 129`firewall`=`<boolean>` ;;
c2993fe5
DM
130
131Controls whether this interface's firewall rules should be used.
132
133`gw`=`<GatewayIPv4>` ;;
134
135Default gateway for IPv4 traffic.
136
137`gw6`=`<GatewayIPv6>` ;;
138
139Default gateway for IPv6 traffic.
140
141`hwaddr`=`<XX:XX:XX:XX:XX:XX>` ;;
142
95895385 143A common MAC address with the I/G (Individual/Group) bit not set.
c2993fe5 144
2489d6df 145`ip`=`<(IPv4/CIDR|dhcp|manual)>` ;;
c2993fe5
DM
146
147IPv4 address in CIDR format.
148
2489d6df 149`ip6`=`<(IPv6/CIDR|auto|dhcp|manual)>` ;;
c2993fe5
DM
150
151IPv6 address in CIDR format.
152
013dc89f 153`mtu`=`<integer> (64 - N)` ;;
c2993fe5
DM
154
155Maximum transfer unit of the interface. (lxc.network.mtu)
156
157`name`=`<string>` ;;
158
159Name of the network device as seen from inside the container. (lxc.network.name)
160
161`rate`=`<mbps>` ;;
162
163Apply rate limiting to the interface
164
013dc89f 165`tag`=`<integer> (1 - 4094)` ;;
c2993fe5
DM
166
167VLAN tag for this interface.
168
169`trunks`=`<vlanid[;vlanid...]>` ;;
170
171VLAN ids to pass through the interface
172
013dc89f 173`type`=`<veth>` ;;
c2993fe5
DM
174
175Network interface type.
176
013dc89f 177`onboot`: `<boolean>` ('default =' `0`)::
71e16346
DM
178
179Specifies whether a VM will be started during system bootup.
180
013dc89f 181`ostype`: `<alpine | archlinux | centos | debian | fedora | gentoo | opensuse | ubuntu | unmanaged>` ::
71e16346 182
c2993fe5 183OS type. This is used to setup configuration inside the container, and corresponds to lxc setup scripts in /usr/share/lxc/config/<ostype>.common.conf. Value 'unmanaged' can be used to skip and OS specific setup.
71e16346 184
013dc89f 185`protection`: `<boolean>` ('default =' `0`)::
71e16346 186
c2993fe5 187Sets the protection flag of the container. This will prevent the CT or CT's disk remove/update operation.
71e16346 188
7cbed89a 189`rootfs`: `[volume=]<volume> [,acl=<1|0>] [,mountoptions=<opt[;opt...]>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346
DM
190
191Use volume as container root.
192
013dc89f 193`acl`=`<boolean>` ;;
c2993fe5
DM
194
195Explicitly enable or disable ACL support.
196
7cbed89a
TL
197`mountoptions`=`<opt[;opt...]>` ;;
198
199Extra mount options for rootfs/mps.
200
013dc89f 201`quota`=`<boolean>` ;;
c2993fe5
DM
202
203Enable user quotas inside the container (not supported with zfs subvolumes)
204
5d9c884c
DM
205`replicate`=`<boolean>` ('default =' `1`);;
206
207Will include this volume to a storage replica job.
208
013dc89f 209`ro`=`<boolean>` ;;
c2993fe5 210
de0983cb
DM
211Read-only mount point
212
013dc89f 213`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
214
215Mark this non-volume mount point as available on all nodes.
216+
217WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
218
219`size`=`<DiskSize>` ;;
220
221Volume size (read only value).
222
223`volume`=`<volume>` ;;
224
225Volume, device or directory to mount into the container.
226
013dc89f 227`searchdomain`: `<string>` ::
71e16346 228
c2993fe5 229Sets DNS search domains for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346
DM
230
231`startup`: `[[order=]\d+] [,up=\d+] [,down=\d+] ` ::
232
c2993fe5 233Startup and shutdown behavior. Order is a non-negative number defining the general startup order. Shutdown in done with reverse ordering. Additionally you can set the 'up' or 'down' delay in seconds, which specifies a delay to wait before the next VM is started or stopped.
71e16346 234
013dc89f 235`swap`: `<integer> (0 - N)` ('default =' `512`)::
71e16346
DM
236
237Amount of SWAP for the VM in MB.
238
5c1699e5
TL
239`tags`: `<string>` ::
240
241Tags of the Container. This is only meta information.
242
013dc89f 243`template`: `<boolean>` ('default =' `0`)::
71e16346
DM
244
245Enable/disable Template.
246
013dc89f 247`tty`: `<integer> (0 - 6)` ('default =' `2`)::
71e16346
DM
248
249Specify the number of tty available to the container
250
013dc89f 251`unprivileged`: `<boolean>` ('default =' `0`)::
71e16346 252
c2993fe5 253Makes the container run as unprivileged user. (Should not be modified manually.)
71e16346 254
013dc89f 255`unused[n]`: `<string>` ::
71e16346 256
c2993fe5 257Reference to unused volumes. This is used internally, and should not be modified manually.
71e16346 258