Hi,
I run all my LXC container unprivileged.
Now and then I have issues with systemd and/or logrotate and some more services not starting.
I resolve the issues with lxc.apparmor.profile unconfined in the LXC conf file.
But I could resolve it by setting nested=1 option in LXC conf file.
So, what is more secure?
What does expose more risk?
Thanx for an explanation.
I run all my LXC container unprivileged.
Now and then I have issues with systemd and/or logrotate and some more services not starting.
I resolve the issues with lxc.apparmor.profile unconfined in the LXC conf file.
But I could resolve it by setting nested=1 option in LXC conf file.
So, what is more secure?
What does expose more risk?
Thanx for an explanation.