[libvirt-users] libvirt-lxc capabilities mknod

jsl6uy js16uy js16uy at gmail.com
Wed Aug 17 17:38:10 UTC 2016


Hello all, hope all is well

Issue: Any way to give granular mknod capabilities to a container? Only
allow creation of specific device?

bit of background

Have a laptop running arch and libvirt
loading an arch lxc container created from lxc-create
Overall container is up and running, I use it for vpn connections

Initially it would not setup of the tun device. Previously using just the
lxc tool set, I can edit the lxc.conf config file for the container and
allow device creation of just the tun device.

In libvirt I can add capabilities for mknod, but seems to be blanket for
any device creation within the container? Is this correct?

Thanks and Regards
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/libvirt-users/attachments/20160817/7e4bfb49/attachment.htm>


More information about the libvirt-users mailing list