Index
- Part 1: Introduction
- Part 2: Basic configuration files
- Part 3: Creating an unprivileged container on Slackware
- Part 4: Scripts overview
- Part 5: Natting example
- Part 6: Migrating to Slackware-current - LXC-7 - cgroup2
- Browse the scripts' folder
- Changelog
Let's see how to manage unprivileged containers also in Slackware-current (16.0 to be), which -at the time I'm writing- ships kernel-7.2.x, lxc-7.0 and libcgroups-3.2.0.
Version 7 of LXC dropped cgroup v1, so we have to use cgroup v2. Thanks to 0XBF for the big support in the cgroup v2 settings as far as the limits inside the containers are concerned.
First of all, enable cgroup2 in /etc/default/cgroups
# Which version of cgroups should we mount, version 1 or version 2? # Please note that the rc.cgred init script (as well as the cgrulesengd # utility itself) will not function with cgroups version 2. Upstream # did not implement support for this since systemd handles it (of course). CGROUPS_VERSION=2 # A list of controllers to enable in the root cgroup.subtree_control file. # These are only used for cgroup version 2 configurations. Note that enabling # the 'cpu' controller will cause the kernel to no longer use real-time # scheduling. For a full list of available controllers, examine the contents # of /sys/fs/cgroup/cgroup.controllers. The following commented list is a # typical full list of controllers, while the shorter one is a typical default list # used on systemd/logind systems. # Warning: the stock kernel has CONFIG_RT_GROUP_SCHED=y. Adding 'cpu' here # will silently prevent real-time scheduling for processes in user sessions # (PipeWire, JACK, rtkit). Boot with rt_group_sched=0 if you need both. CGROUP_V2_CONTROLLERS="cpuset io memory pids misc dmem" #CGROUP_V2_CONTROLLERS="memory pids" # Options to pass when mounting cgroup2. Prefix options with '-o'. # The following example adds the 'nsdelegate' option to the mount # of cgroup2: CGROUP_V2_MOUNT_OPTS="-o nsdelegate"
Disable rc.cgconfig and rc.cgred at boot time:
chmod -x /etc/rc.d/rc.cgconfig /etc/rc.d/rc.cgred
Replace the file /etc/lxc/lxc-common.conf in this way (all lxc.cgroup.* options are now lxc.cgroup2.*):
lxc.net.0.type = veth
lxc.net.0.flags = up
lxc.net.0.link = lxcbr0
lxc.net.0.name = eth0
lxc.net.0.hwaddr = 00:16:3e:xx:xx:xx
lxc.tty.max = 1
lxc.pty.max = 1024
lxc.cgroup2.devices.deny = a
# /dev/null and zero
lxc.cgroup2.devices.allow = c 1:3 rwm
lxc.cgroup2.devices.allow = c 1:5 rwm
# consoles
lxc.cgroup2.devices.allow = c 5:1 rwm
lxc.cgroup2.devices.allow = c 5:0 rwm
lxc.cgroup2.devices.allow = c 4:0 rwm
lxc.cgroup2.devices.allow = c 4:1 rwm
# /dev/{,u}random
lxc.cgroup2.devices.allow = c 1:9 rwm
lxc.cgroup2.devices.allow = c 1:8 rwm
lxc.cgroup2.devices.allow = c 136:* rwm
lxc.cgroup2.devices.allow = c 5:2 rwm
# rtc
lxc.cgroup2.devices.allow = c 254:0 rwm
# we don't trust even the root user in the container, better safe than sorry.
# comment out only if you know what you're doing.
lxc.cap.drop = sys_module mknod mac_override mac_admin sys_time setfcap setpcap
# you can try also this alternative to the line above, whatever suits you better.
#lxc.cap.drop=sys_admin
# proc & sys, remove from /etc/fstab
lxc.mount.auto = proc:mixed sys:ro
When you start the containers, a cgroup structure is created in /sys/fs/cgroup:
# tree -d --noreport /sys/fs/cgroup /sys/fs/cgroup ├── 1 │ ├── delegated │ └── session ├── elogind └── lxc-containers ├── c1 │ ├── delegated │ │ ├── lxc.monitor.c1 │ │ └── lxc.payload.c1 │ └── session ├── c2 │ ├── delegated │ │ ├── lxc.monitor.c2 │ │ └── lxc.payload.c2 │ └── session ├── c3 │ ├── delegated │ │ ├── lxc.monitor.c3 │ │ └── lxc.payload.c3 │ └── session
Now you are able to setup container's limits inside each config file. For example, to set a memory limit to the container test just add the following in its config file:
lxc.cgroup2.memory.max = 256M
Restart the container and check that the memory limit has been set:
cat /sys/fs/cgroup/lxc-containers/test/delegated/lxc.payload.test/memory.max 268435456
Be aware that, if you want to use my scripts with slackware-current you have to download the main branch of my github instead of the latest release:
git clone https://github.com/sagredo-dev/LXC-scripts.git

