Last active
July 28, 2019 13:02
-
-
Save rsyuzyov/fb2d45df87c73c58f2d703c3f3c573e3 to your computer and use it in GitHub Desktop.
proxmoxs-notes
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| qm importdisk vm-id /tmp/disk.vhd pve-storage-name | |
| === lxc === | |
| https://pve.proxmox.com/wiki/Unprivileged_LXC_containers | |
| pct list | |
| pct set 100 -mp0 /mnt/bindmounts/shared,mp=/shared | |
| Права apparmor для контейнеров: /etc/apparmor.d/lxc/ | |
| ====== | |
| nfs into lxc: | |
| https://pztrn.name/blog/nfs-%D1%81%D0%B5%D1%80%D0%B2%D0%B5%D1%80-%D0%B2-lxc-%D0%BA%D0%BE%D0%BD%D1%82%D0%B5%D0%B9%D0%BD%D0%B5%D1%80%D0%B5/ | |
| Пусть ID контейнера - это 100. Тогда надо в конфиги: | |
| /etc/pve/lxc/100.conf | |
| /var/lib/lxc/100/config | |
| Добавить строчку: | |
| lxc.aa_profile = unconfined | |
| Делать это необходимо при выключенном контейнере. После запуска сервер NFS будет работать. | |
| Без отключения apparmor: | |
| https://gist.github.com/rwenz3l/0907385f6a6690c34eb8e36fa73d8405 | |
| Еще проще: | |
| https://github.com/lxc/lxd/issues/3989 | |
| lxc launch ubuntu:16.04 nfs -c security.privileged=true -c raw.apparmor="mount fstype=rpc_pipefs, mount fstype=nfsd," | |
| Нашел еще способ (пока не проверял): | |
| https://forum.proxmox.com/threads/mounting-nfs-in-lxc-not-working-since-latest-update.47815/ | |
| It has to add profile "lxc.apparmor.profile: lxc-container-default-cgns" to each LXC ID config file. | |
| ==== | |
| Раблокировать контейнер: | |
| pct unlock ctid |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment