Whats the advantages of idmap in unprivileged containers vs controlling IDs (and permissions) at the host?

seanshankus

New Member
Dec 15, 2021
5
0
1
51
like a lot of folks i've been struggling getting the a bind mount working in an unprivileged container with proper permissions on the share. In doing research i came across this reddit thread (Commenter deleted their comments so its actually an unddit). One solution suggested was to not do the lxc.idmap within the container config and instead manage the UID/GUI at the host. THey spell it out better than i just did. So i get what the commenter says and outside of more configuration at the host, what are the other CONs? i'm guessing you couldn't do this in a clustered environment (or at least it would be a LOT more coordination). But for a single home lab situation. What are the pross/cons of this solution?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!