ubuntu.common.conf.in revision d3928441889e4c91d986bbbb41e791e18d2b1e91
e8ceec219830407bded84634716d37d45d3a5872Julian Kornberger# Default pivot location
e8ceec219830407bded84634716d37d45d3a5872Julian Kornberger# Default mount entries
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehaselxc.mount.entry = proc proc proc nodev,noexec,nosuid 0 0
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehaselxc.mount.entry = sysfs sys sysfs defaults 0 0
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehaselxc.mount.entry = /sys/fs/fuse/connections sys/fs/fuse/connections none bind,optional 0 0
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehaselxc.mount.entry = /sys/kernel/debug sys/kernel/debug none bind,optional 0 0
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehaselxc.mount.entry = /sys/kernel/security sys/kernel/security none bind,optional 0 0
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehaselxc.mount.entry = /sys/fs/pstore sys/fs/pstore none bind,optional 0 0
afd1d888784385307c9c0544597a513c2008d342Eugen Kuksa# Default console settings
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehase# Default capabilities
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehaselxc.cap.drop = sys_module mac_admin mac_override sys_time
afd1d888784385307c9c0544597a513c2008d342Eugen Kuksa# When using LXC with apparmor, the container will be confined by default.
afd1d888784385307c9c0544597a513c2008d342Eugen Kuksa# If you wish for it to instead run unconfined, copy the following line
afd1d888784385307c9c0544597a513c2008d342Eugen Kuksa# (uncommented) to the container's configuration file.
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehase# To support container nesting on an Ubuntu host while retaining most of
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehase# apparmor's added security, use the following two lines instead.
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehase#lxc.aa_profile = lxc-container-default-with-nesting
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehase#lxc.hook.mount = /usr/share/lxc/hooks/mountcgroups
37376063320bfb86e0cb9fd4eda25c52c4a667b8Tim Reddehase# Default cgroup limits
e8ceec219830407bded84634716d37d45d3a5872Julian Kornberger## Allow any mknod (but not using the node)
afd1d888784385307c9c0544597a513c2008d342Eugen Kuksa## /dev/{,u}random