]> git.proxmox.com Git - pve-docs.git/blame - pct.conf.5-opts.adoc
update static data and schema definitions
[pve-docs.git] / pct.conf.5-opts.adoc
CommitLineData
4d47f125 1`arch`: `<amd64 | arm64 | armhf | i386>` ('default =' `amd64`)::
71e16346
DM
2
3OS architecture type.
4
013dc89f 5`cmode`: `<console | shell | tty>` ('default =' `tty`)::
71e16346 6
c2993fe5 7Console mode. By default, the console command tries to open a connection to one of the available tty devices. By setting cmode to 'console' it tries to attach to /dev/console instead. If you set cmode to 'shell', it simply invokes a shell inside the container (no login).
71e16346 8
013dc89f 9`console`: `<boolean>` ('default =' `1`)::
71e16346
DM
10
11Attach a console device (/dev/console) to the container.
12
013dc89f 13`cores`: `<integer> (1 - 128)` ::
de0983cb
DM
14
15The number of cores assigned to the container. A container can use all available cores by default.
16
013dc89f 17`cpulimit`: `<number> (0 - 128)` ('default =' `0`)::
71e16346
DM
18
19Limit of CPU usage.
20+
c2993fe5 21NOTE: If the computer has 2 CPUs, it has a total of '2' CPU time. Value '0' indicates no CPU limit.
71e16346 22
013dc89f 23`cpuunits`: `<integer> (0 - 500000)` ('default =' `1024`)::
71e16346 24
c2993fe5 25CPU weight for a VM. Argument is used in the kernel fair scheduler. The larger the number is, the more CPU time this VM gets. Number is relative to the weights of all the other running VMs.
71e16346
DM
26+
27NOTE: You can disable fair-scheduler configuration by setting this to 0.
28
013dc89f 29`description`: `<string>` ::
71e16346
DM
30
31Container description. Only used on the configuration web interface.
32
c5aa7e14 33`features`: `[force_rw_sys=<1|0>] [,fuse=<1|0>] [,keyctl=<1|0>] [,mknod=<1|0>] [,mount=<fstype;fstype;...>] [,nesting=<1|0>]` ::
4d47f125
TL
34
35Allow containers access to advanced features.
36
c5aa7e14
TL
37`force_rw_sys`=`<boolean>` ('default =' `0`);;
38
39Mount /sys in unprivileged containers as `rw` instead of `mixed`. This can break networking under newer (>= v245) systemd-network use.
40
e2d681b3
TL
41`fuse`=`<boolean>` ('default =' `0`);;
42
43Allow using 'fuse' file systems in a container. Note that interactions between fuse and the freezer cgroup can potentially cause I/O deadlocks.
44
4d47f125
TL
45`keyctl`=`<boolean>` ('default =' `0`);;
46
47For unprivileged containers only: Allow the use of the keyctl() system call. This is required to use docker inside a container. By default unprivileged containers will see this system call as non-existent. This is mostly a workaround for systemd-networkd, as it will treat it as a fatal error when some keyctl() operations are denied by the kernel due to lacking permissions. Essentially, you can choose between running systemd-networkd or docker.
48
c5aa7e14
TL
49`mknod`=`<boolean>` ('default =' `0`);;
50
51Allow unprivileged containers to use mknod() to add certain device nodes. This requires a kernel with seccomp trap to user space support (5.3 or newer). This is experimental.
52
4d47f125
TL
53`mount`=`<fstype;fstype;...>` ;;
54
55Allow mounting file systems of specific types. This should be a list of file system types as used with the mount command. Note that this can have negative effects on the container's security. With access to a loop device, mounting a file can circumvent the mknod permission of the devices cgroup, mounting an NFS file system can block the host's I/O completely and prevent it from rebooting, etc.
56
57`nesting`=`<boolean>` ('default =' `0`);;
58
59Allow nesting. Best used with unprivileged containers with additional id mapping. Note that this will expose procfs and sysfs contents of the host to the guest.
60
5f26e15b
TL
61`hookscript`: `<string>` ::
62
63Script that will be exectued during various steps in the containers lifetime.
64
013dc89f 65`hostname`: `<string>` ::
71e16346
DM
66
67Set a host name for the container.
68
1c532546 69`lock`: `<backup | create | destroyed | disk | fstrim | migrate | mounted | rollback | snapshot | snapshot-delete>` ::
71e16346
DM
70
71Lock/unlock the VM.
72
013dc89f 73`memory`: `<integer> (16 - N)` ('default =' `512`)::
71e16346
DM
74
75Amount of RAM for the VM in MB.
76
7cbed89a 77`mp[n]`: `[volume=]<volume> ,mp=<Path> [,acl=<1|0>] [,backup=<1|0>] [,mountoptions=<opt[;opt...]>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346 78
c2993fe5
DM
79Use volume as container mount point.
80
013dc89f 81`acl`=`<boolean>` ;;
c2993fe5
DM
82
83Explicitly enable or disable ACL support.
84
013dc89f 85`backup`=`<boolean>` ;;
c2993fe5 86
de0983cb 87Whether to include the mount point in backups (only used for volume mount points).
c2993fe5 88
7cbed89a
TL
89`mountoptions`=`<opt[;opt...]>` ;;
90
91Extra mount options for rootfs/mps.
92
c2993fe5
DM
93`mp`=`<Path>` ;;
94
de0983cb 95Path to the mount point as seen from inside the container.
2c0dde61
DM
96+
97NOTE: Must not contain any symlinks for security reasons.
c2993fe5 98
013dc89f 99`quota`=`<boolean>` ;;
c2993fe5
DM
100
101Enable user quotas inside the container (not supported with zfs subvolumes)
102
5d9c884c
DM
103`replicate`=`<boolean>` ('default =' `1`);;
104
105Will include this volume to a storage replica job.
106
013dc89f 107`ro`=`<boolean>` ;;
c2993fe5 108
de0983cb
DM
109Read-only mount point
110
013dc89f 111`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
112
113Mark this non-volume mount point as available on all nodes.
114+
115WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
116
117`size`=`<DiskSize>` ;;
118
119Volume size (read only value).
120
121`volume`=`<volume>` ;;
122
123Volume, device or directory to mount into the container.
71e16346 124
013dc89f 125`nameserver`: `<string>` ::
71e16346 126
c2993fe5 127Sets DNS server IP address for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346 128
2489d6df 129`net[n]`: `name=<string> [,bridge=<bridge>] [,firewall=<1|0>] [,gw=<GatewayIPv4>] [,gw6=<GatewayIPv6>] [,hwaddr=<XX:XX:XX:XX:XX:XX>] [,ip=<(IPv4/CIDR|dhcp|manual)>] [,ip6=<(IPv6/CIDR|auto|dhcp|manual)>] [,mtu=<integer>] [,rate=<mbps>] [,tag=<integer>] [,trunks=<vlanid[;vlanid...]>] [,type=<veth>]` ::
71e16346
DM
130
131Specifies network interfaces for the container.
132
c2993fe5
DM
133`bridge`=`<bridge>` ;;
134
135Bridge to attach the network device to.
136
013dc89f 137`firewall`=`<boolean>` ;;
c2993fe5
DM
138
139Controls whether this interface's firewall rules should be used.
140
141`gw`=`<GatewayIPv4>` ;;
142
143Default gateway for IPv4 traffic.
144
145`gw6`=`<GatewayIPv6>` ;;
146
147Default gateway for IPv6 traffic.
148
149`hwaddr`=`<XX:XX:XX:XX:XX:XX>` ;;
150
95895385 151A common MAC address with the I/G (Individual/Group) bit not set.
c2993fe5 152
2489d6df 153`ip`=`<(IPv4/CIDR|dhcp|manual)>` ;;
c2993fe5
DM
154
155IPv4 address in CIDR format.
156
2489d6df 157`ip6`=`<(IPv6/CIDR|auto|dhcp|manual)>` ;;
c2993fe5
DM
158
159IPv6 address in CIDR format.
160
013dc89f 161`mtu`=`<integer> (64 - N)` ;;
c2993fe5
DM
162
163Maximum transfer unit of the interface. (lxc.network.mtu)
164
165`name`=`<string>` ;;
166
167Name of the network device as seen from inside the container. (lxc.network.name)
168
169`rate`=`<mbps>` ;;
170
171Apply rate limiting to the interface
172
013dc89f 173`tag`=`<integer> (1 - 4094)` ;;
c2993fe5
DM
174
175VLAN tag for this interface.
176
177`trunks`=`<vlanid[;vlanid...]>` ;;
178
179VLAN ids to pass through the interface
180
013dc89f 181`type`=`<veth>` ;;
c2993fe5
DM
182
183Network interface type.
184
013dc89f 185`onboot`: `<boolean>` ('default =' `0`)::
71e16346
DM
186
187Specifies whether a VM will be started during system bootup.
188
013dc89f 189`ostype`: `<alpine | archlinux | centos | debian | fedora | gentoo | opensuse | ubuntu | unmanaged>` ::
71e16346 190
c2993fe5 191OS type. This is used to setup configuration inside the container, and corresponds to lxc setup scripts in /usr/share/lxc/config/<ostype>.common.conf. Value 'unmanaged' can be used to skip and OS specific setup.
71e16346 192
013dc89f 193`protection`: `<boolean>` ('default =' `0`)::
71e16346 194
c2993fe5 195Sets the protection flag of the container. This will prevent the CT or CT's disk remove/update operation.
71e16346 196
7cbed89a 197`rootfs`: `[volume=]<volume> [,acl=<1|0>] [,mountoptions=<opt[;opt...]>] [,quota=<1|0>] [,replicate=<1|0>] [,ro=<1|0>] [,shared=<1|0>] [,size=<DiskSize>]` ::
71e16346
DM
198
199Use volume as container root.
200
013dc89f 201`acl`=`<boolean>` ;;
c2993fe5
DM
202
203Explicitly enable or disable ACL support.
204
7cbed89a
TL
205`mountoptions`=`<opt[;opt...]>` ;;
206
207Extra mount options for rootfs/mps.
208
013dc89f 209`quota`=`<boolean>` ;;
c2993fe5
DM
210
211Enable user quotas inside the container (not supported with zfs subvolumes)
212
5d9c884c
DM
213`replicate`=`<boolean>` ('default =' `1`);;
214
215Will include this volume to a storage replica job.
216
013dc89f 217`ro`=`<boolean>` ;;
c2993fe5 218
de0983cb
DM
219Read-only mount point
220
013dc89f 221`shared`=`<boolean>` ('default =' `0`);;
de0983cb
DM
222
223Mark this non-volume mount point as available on all nodes.
224+
225WARNING: This option does not share the mount point automatically, it assumes it is shared already!
c2993fe5
DM
226
227`size`=`<DiskSize>` ;;
228
229Volume size (read only value).
230
231`volume`=`<volume>` ;;
232
233Volume, device or directory to mount into the container.
234
013dc89f 235`searchdomain`: `<string>` ::
71e16346 236
c2993fe5 237Sets DNS search domains for a container. Create will automatically use the setting from the host if you neither set searchdomain nor nameserver.
71e16346
DM
238
239`startup`: `[[order=]\d+] [,up=\d+] [,down=\d+] ` ::
240
c2993fe5 241Startup and shutdown behavior. Order is a non-negative number defining the general startup order. Shutdown in done with reverse ordering. Additionally you can set the 'up' or 'down' delay in seconds, which specifies a delay to wait before the next VM is started or stopped.
71e16346 242
013dc89f 243`swap`: `<integer> (0 - N)` ('default =' `512`)::
71e16346
DM
244
245Amount of SWAP for the VM in MB.
246
5c1699e5
TL
247`tags`: `<string>` ::
248
249Tags of the Container. This is only meta information.
250
013dc89f 251`template`: `<boolean>` ('default =' `0`)::
71e16346
DM
252
253Enable/disable Template.
254
013dc89f 255`tty`: `<integer> (0 - 6)` ('default =' `2`)::
71e16346
DM
256
257Specify the number of tty available to the container
258
013dc89f 259`unprivileged`: `<boolean>` ('default =' `0`)::
71e16346 260
c2993fe5 261Makes the container run as unprivileged user. (Should not be modified manually.)
71e16346 262
c5aa7e14 263`unused[n]`: `[volume=]<volume>` ::
71e16346 264
c2993fe5 265Reference to unused volumes. This is used internally, and should not be modified manually.
71e16346 266
c5aa7e14
TL
267`volume`=`<volume>` ;;
268
269The volume that is not used currently.
270