Question about LXC and security

Lecaf_

New Member
Jan 2, 2025
4
0
1
hi
I plan to install some internet facing services on LXC, and I 'm reviewing the security.
The scenario is the worst case: the attacker has RCE with root privileges on the LXC.
will he be contained there?

The LXC is of course unprivileged.
I'm not considering any 0days of the kernel/OS, these are part of life and will be pathed hopefully sooner than later.

I noticed for example, that from the LXC lsblk shows me all PVE disks or that netdata shows all IO rates and much more.

Is there any additional hardening steps to safeguard the PVE host? what are the risks for the host and the other VMs/LXC
Is VM is the better/only way to go?

Thoughts and prayers are welcome... :)

m
 
The root user in unprivileged containers is not special, so such an attack might fail quickly but containers do share the kernel with Proxmox.
Maybe add another layer and run one or more Proxmox VMs inside Proxmox and run a few unprivileged containers in each (so that separate groups of services don't get compromised at once).
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!