Search results for query: idmap

  1. B

    LXC Containers with CephFS Mountpoints Fail to Start at Boot

    ...netfs: FS-Cache loaded Nov 12 00:34:43 rackbeast kernel: Key type cifs.spnego registered Nov 12 00:34:43 rackbeast kernel: Key type cifs.idmap registered Nov 12 00:34:43 rackbeast kernel: CIFS: Attempting to mount //69.59.18.197/mnt Nov 12 00:34:44 rackbeast kernel: Key type ceph registered...
  2. C

    [SOLVED] uid/gid mapping to unpriv. lxc breaks permissions in guest

    ...ID mapping. I have an unprivileged container with a user/group pair 107:114 mapped to the hosts 1002:1002 pair with the following config: lxc.idmap: u 0 100000 107 lxc.idmap: u 107 1002 1 lxc.idmap: u 108 100108 65428 lxc.idmap: g 0 100000 114 lxc.idmap: g 114 1002 1 lxc.idmap: g 115 100115...
  3. C

    [SOLVED] UID/GID mapping für unprivilegiertem LXC löst Berechtigungen im Gast auf

    ...unter /etc/ ist (kein bind mount!). Nun habe ich die uid/gid jeweils nach außen auf die host ids 1002:1002 gemappt. Sieht wie folgt aus: lxc.idmap: u 0 100000 107 lxc.idmap: u 107 1002 1 lxc.idmap: u 108 100108 65428 lxc.idmap: g 0 100000 114 lxc.idmap: g 114 1002 1 lxc.idmap: g 115 100115...
  4. A

    LXC idmap bug

    Solution (Workaround) I found a workaround that eliminates the need to manually add idmap entries to the container's config. Instead, I set the mappings as follows: Host_UID = CT_UID + 100000 Host_GID = CT_GID + 100000 This approach bypasses the need to specify idmap` configurations directly...
  5. B

    Radarr lxc "Unable to add root folder"

    ...a group 'media-group' (with gid 1200), and added root to this group usermod -aG media-group root on proxmox host, added a mountpoint and idmap for 'media-group' to the config file /etc/pve/lxc/[lxc_id].conf mp0: /mnt/truenas-media,mp=/mnt/media,backup=0 lxc.idmap: u 0 100000 65536 lxc.idmap...
  6. I

    CT migration from one node to another

    ...lxc.apparmor.profile = generated lxc.apparmor.allow_nesting = 1 lxc.mount.auto = sys:mixed lxc.monitor.unshare = 1 lxc.idmap = u 0 100000 65536 lxc.idmap = g 0 100000 65536 lxc.tty.max = 2 lxc.environment = TERM=linux lxc.uts.name = docker lxc.cgroup2.memory.max = 2147483648...
  7. D

    failed LXC restore: ACL invalid

    ...swap: 512 tags: proxmox-helper-scripts unprivileged: 1 lxc.mount.entry: /storage/backups/restic mnt/restic none bind 0 0 lxc.idmap: u 0 100000 1000 lxc.idmap: g 0 100000 1000 lxc.idmap: u 1000 1002 1 lxc.idmap: g 1000 1002 1 lxc.idmap: u 1001 101001 64535 lxc.idmap: g 1001 101001 64535...
  8. M

    LXC bind mount permissions

    ...29 13:36 data Tried to map the UID/GID as well as the appropriate entries in /etc/subuid and /etc/subgid (root:3000:1 root:100000:65536). lxc.idmap: u 0 3000 1 lxc.idmap: g 0 3000 1 lxc.idmap: u 100000 100000 65536 lxc.idmap: g 100000 100000 65536 After making those changes, rebooting the...
  9. W

    Another Unprivileged LXC container issue

    ...onboot: 1 ostype: debian rootfs: cts:205/vm-205-disk-0.raw,size=250G swap: 512 tags: proxmox-helper-scripts unprivileged: 1 lxc.idmap: u 0 100000 568 lxc.idmap: g 0 100000 568 lxc.idmap: u 568 568 1 lxc.idmap: g 568 568 1 lxc.idmap: u 569 100569 64967 lxc.idmap: g 569 100569 64967 I updated...
  10. F

    PVE 8.2 WebAccess und SSH nicht möglich

    ...with error -2 [ 56.137939] cfg80211: failed to load regulatory.db [ 56.279309] Key type cifs.spnego registered [ 56.279325] Key type cifs.idmap registered Journalctl: Oct 24 06:27:19 pve systemd[1]: Starting apt-daily-upgrade.service - Daily apt upgrade and clean activities... Oct 24...
  11. A

    LXC idmap bug

    ...to give this service rw access to a folder which is mounted in the pve-node: 15 drwxr-xr-x 4 radarr radarr 19 Oct 22:44 data So I did: lxc.idmap: u 0 1070 1 lxc.idmap: u 1 100001 65534 lxc.idmap: g 0 1070 1 lxc.idmap: g 1 100001 65534 This should theoretically map the container’s root...
  12. K

    What am I doing wrong with my user mapping

    I wasn't able to write to my bind mount so I followed the guide here, however I'm unsure why i'm hitting the error newuidmap failed to write mapping "newuidmap: uid range [1005-1006) -> [1005-1006) not allowed" What am I missing? root@isaac:~# cat /etc/subuid root:100000:65536 root@isaac:~#...
  13. N

    How to add hard drive attached to host to an LXC

    ...In case I copied something wrong, here are relevent bit of the lxc conf file: mp0: /mnt/glusterfs/influxdb_data,mp=/mnt/influxdb_data lxc.idmap: u 0 100000 999 lxc.idmap: u 999 999 1 lxc.idmap: u 1000 101000 64536 lxc.idmap: g 0 100000 996 lxc.idmap: g 996 996 1 lxc.idmap: g 997 100997 64539...
  14. fschauer

    LXC idmap bug

    ...container to UID 1070 on the host. Here is an example where UID and GID 1010 in the container are mapped to UID and GID 1070 on the host: lxc.idmap = u 0 100000 1010 lxc.idmap = u 1010 1070 1 lxc.idmap = u 1011 101011 64525 lxc.idmap = g 0 100000 1010 lxc.idmap = g 1010 1070 1 lxc.idmap = g...
  15. fschauer

    How to add hard drive attached to host to an LXC

    ...UID 999 on the host - GID 996 in the container to GID 996 on the host First map UIDs 0-998 in the container to 100000-100998 on the host: lxc.idmap = u 0 100000 999 Then map UID 999 in the container to 999 on the host: lxc.idmap = u 999 999 1 And finally map the remaining UIDs 1000-65535...
  16. A

    LXC idmap bug

    Thanks for your answer yes, but that's ok. Also this is missing one uid/gid mapping. Nevertheless, I just tried your code and still doesn't work.
  17. fschauer

    LXC idmap bug

    ...on the host - ... What you actually want is: - uid 1 in the ct to uid 100001 on the host - uid 2 in the ct to uid 100002 on the host - ... To fix this, change your mapping configuration to this: lxc.idmap: u 0 1070 1 lxc.idmap: u 1 100001 65534 lxc.idmap: g 0 1070 1 lxc.idmap: g 1 100001 65534
  18. A

    LXC idmap bug

    ...an Alpine LXC, mapping uid & gid from 0(root) CT to 1070(nextcloud) host. All files ownerships are shifted 1 place! What's going on here? lxc.idmap: u 0 1070 1 lxc.idmap: u 1 100000 65535 lxc.idmap: g 0 1070 1 lxc.idmap: g 1 100000 65535 alpine-nextcloud:~# getent passwd...
  19. C

    Rootless Docker inside unprivileged LXC container

    ...and /etc/subgid of Proxmox. For example, I changed the default 100000:65536 to 100000:165536 then on the LXC, you need to map with: lxc.idmap: u 0 100000 165536 lxc.idmap: g 0 100000 165536 However, I'm having trouble getting docker to run, and it constantly errors out with "medium not...