Re: [Lxc-users] Setting yama/ptrace_scope to 0 inside container?

2012-09-13 Thread Serge Hallyn
Quoting Dan Kegel (d...@kegel.com): I'd like to strace a stray process, but in Ubuntu 12.04, to do that you have to do echo 0 | sudo tee /proc/sys/kernel/yama/ptrace_scope This fails inside an LXC (ephemeral) container. But since there's only one kernel, you can do that in the host, and

Re: [Lxc-users] LXC in production envivroment

2012-09-13 Thread Stuart Yoder
I would not use lxc for shared vps setup (like openvz) at this moment due to some unsolved security issues. I've seen security issues with lxc mentioned in a few places, but nothing very specific (one thing specific was something to do with /proc filtering). (I've googled a bit, but it's hard

Re: [Lxc-users] LXC in production envivroment

2012-09-13 Thread Stéphane Graber
On 12-09-13 06:56 PM, Stuart Yoder wrote: I would not use lxc for shared vps setup (like openvz) at this moment due to some unsolved security issues. I've seen security issues with lxc mentioned in a few places, but nothing very specific (one thing specific was something to do with /proc