[SOLVED] PMG LXC container: Question about nesting and security

laurensb

New Member
Mar 9, 2020
11
0
1
Running PMG as LXC container on Proxmox Virtual Environment. Just upgraded it from 6.4 to 7.0.

When troubleshooting slow SSH logins I found the solution is to enable nesting (https://forum.proxmox.com/threads/delay-to-log-in-ssh-session-after-upgrade-from-6-x-to-7-x.92755/), and it worked, SSH is fast again. Enabling nesting also fixed some syncing problems between nodes (https://forum.proxmox.com/threads/issue-with-sync.94151/). However, according to Oguz it's considered less secure to enable it on a container: https://forum.proxmox.com/threads/question-on-nested-option-lxc-container.86497/post-379642.

PMG 6.x didn't need it, is it intended that 7.x needs nesting? Seems a bit awkward that security is weakened with 7.x.
 

Stoiko Ivanov

Proxmox Staff Member
Staff member
May 2, 2018
6,192
864
148
PMG 6.x didn't need it, is it intended that 7.x needs nesting? Seems a bit awkward that security is weakened with 7.x.
PMG 6.x was based on debian buster and had thus an older version of systemd packaged then 7.x which is based on debian bullseye.
newer versions of systemd need access to proc in order to do their own isolation of unit's

since your PMG container is unprivileged enabling nesting should not pose a too large security risk (a regular user on your system can also not elevate their privileges by having access to /proc and /sys)

I hope this explains it!
 
  • Like
Reactions: suriv

laurensb

New Member
Mar 9, 2020
11
0
1
Aha, clear! Thanks for the quick clarification.

As I understand this will be the same for all future (upgraded and new) Debian 11 and other containers with new systemd version. Might be an idea to make a note in the upgrade guides for PVE and PMG.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get your own in 60 seconds.

Buy now!