I'm use priveleged ct.
arch: amd64
cores: 2
features: fuse=1,mknod=1,nesting=1
hostname: host
memory: 2048
net0: name=eth0,bridge=vmbr0,firewall=1,hwaddr=52:C3:CE:EF:A1:B6,ip=dhcp,type=veth
ostype: ubuntu
rootfs: local-zfs:subvol-100-disk-1,size=8G
swap: 512
lxc.cgroup.devices.allow: c 1:* rwm...