Re: [lxc-users] LXC Memory LImits

2020-11-09 Thread Fajar A. Nugraha
On Mon, Nov 9, 2020 at 3:35 PM Harald Dunkel wrote: > > > On 11/4/20 11:30 AM, Atif Ghaffar wrote: > > > > I find this document useful for resource limits. > > > > https://stgraber.org/2016/03/26/lxd-2-0-resource-control-412/ > > >

Re: [lxc-users] ghost services on LXC containers

2020-09-09 Thread Fajar A. Nugraha
On Thu, Aug 13, 2020 at 5:47 PM Harald Dunkel wrote: > > On 8/13/20 12:32 PM, Fajar A. Nugraha wrote: > > Try (two times, once inside the container, once inside the host): > > - cat /proc/self/cgroup > > - ls -la /proc/self/ns > > On the host: > > root@il0

Re: [lxc-users] ghost services on LXC containers

2020-08-13 Thread Fajar A. Nugraha
On Thu, Aug 13, 2020 at 5:23 PM Harald Dunkel wrote: > > On 8/13/20 9:02 AM, Harald Dunkel wrote: > > > > # cat /sys/fs/cgroup/unified/system.slice/zabbix-agent.service/cgroup.procs > > 0 > > 0 > > 0 > > 0 > > 0 > > 0 > > > > > > PID 0 is not valid here, AFAICT. And zabbix-agent isn't even

Re: [lxc-users] lxd-client on 20.04 focal

2020-07-12 Thread Fajar A. Nugraha
On Mon, Jul 13, 2020 at 7:50 AM Logan V. wrote: > > Typically I use lxd-client in jobs that run in docker containers, so the > container has the lxd-client apt package installed. Now it seems that the lxd > and lxd-client are just shims for the snap. > > Since it seems like installing snaps in

Re: [lxc-users] AppArmor denies connect operation inside container

2020-07-06 Thread Fajar A. Nugraha
On Tue, Jul 7, 2020 at 2:40 AM Joshua Schaeffer wrote: > > Looking for some help with getting slapd to be able to connect to saslauthd > inside an LXD container. Whenever slapd needs to connect to the socket I see > the following error message in the host's kernel log: > > Jul 6 13:27:17

Re: [lxc-users] Intermittent network issue with containers

2020-07-01 Thread Fajar A. Nugraha
On Wed, Jul 1, 2020 at 1:05 PM Joshua Schaeffer wrote: > And the really odd part is that if I try to actually ping *from* the > container *to* my local box it works AND afterwards my original ping *from* > my local box *to* the container starts to work. I had a similar problem on a vmware

Re: [lxc-users] Running unprotected system container

2020-06-20 Thread Fajar A. Nugraha
On Sat, Jun 20, 2020 at 3:07 PM Fajar A. Nugraha wrote: > > On Tue, Jun 16, 2020 at 6:26 PM Koehler, Yannick > wrote: > > > > Hi Fajar, > > > > If I use a Ubuntu image it works fine and I can run bash within the > > container. So I know the issue

Re: [lxc-users] Running unprotected system container

2020-06-20 Thread Fajar A. Nugraha
On Tue, Jun 16, 2020 at 6:26 PM Koehler, Yannick wrote: > > Hi Fajar, > > If I use a Ubuntu image it works fine and I can run bash within the > container. So I know the issue is somehow related to my imported image but I > fail to understand why at this time. > > All the files in the imported

Re: [lxc-users] Running unprotected system container

2020-06-15 Thread Fajar A. Nugraha
On Mon, Jun 15, 2020 at 9:23 PM Koehler, Yannick wrote: > > I am still faced with the situation where if I run sh inside my container > then any command I try to execute such as /bin/ls returns permission denied. > > Any clue as to what I need to adjust to enable me to get inside my container >

Re: [lxc-users] Running unprotected system container

2020-06-12 Thread Fajar A. Nugraha
On Sat, Jun 13, 2020 at 9:41 AM Koehler, Yannick wrote: > > Hi, > > I am in a situation where we desire to run our old OS environment inside > Ubuntu Core. So far we have identified LXD as being a candidate to enable us > to run our past Linux OS environment within the new one. > > At this

Re: [lxc-users] Storage pool grew larger than the host disc

2020-03-29 Thread Fajar A. Nugraha
On Mon, Mar 30, 2020 at 2:40 AM Yakov wrote: > > I need to shrink the default.img some how. Please help! Short version: you can't. > Our production system is down, sigh. I'm pretty sure (at least last time I tried it) there's a warning NOT to use loopback zfs for production environment. Your

Re: [lxc-users] Networking

2020-03-24 Thread Fajar A. Nugraha
On Mon, Mar 23, 2020 at 11:48 PM Saint Michael wrote: > > It is supported, there is no error, but there is no communication at all with > the gateway. If you start the same exact network configuration in the > container with the type=phys, it works fine, ergo, the issue is type=ipvlan. "exact

Re: [lxc-users] Networking

2020-03-23 Thread Fajar A. Nugraha
On Fri, Mar 20, 2020 at 5:36 PM Saint Michael wrote: > > I use plain LXC, not LXD. is ipvlan supported? https://linuxcontainers.org/lxc/manpages//man5/lxc.container.conf.5.html -- Fajar ___ lxc-users mailing list lxc-users@lists.linuxcontainers.org

Re: [lxc-users] Networking

2020-03-19 Thread Fajar A. Nugraha
On Thu, Mar 19, 2020 at 12:02 AM Saint Michael wrote: > > The question is: how do we share the networking from the host to the > containers, all of if. each container will use one IP, but they could see all > the IPs in the host. This will solve the issue, since a single network > interface,

Re: [lxc-users] Unprivileged networking option?

2020-03-05 Thread Fajar A. Nugraha
On Thu, Mar 5, 2020 at 11:43 PM Ede Wolf wrote: > > Hello Andrey, > > thanks for getting back to me. The reason for unpriviledged containers > is basically user id separation. > > I fancy the idea that each container has its own id (range) and the user > ids are not being shared between

Re: [lxc-users] Migrating from LXC to LXD

2020-01-22 Thread Fajar A. Nugraha
On Thu, Jan 23, 2020 at 4:22 AM Michael Eager wrote: > > On 1/21/20 9:47 PM, Fajar A. Nugraha wrote: > > On Wed, Jan 22, 2020 at 9:01 AM Michael Eager wrote: > >> devices: > >> eth0: > >> name: eth0 > >> nictype: macvlan > >&g

Re: [lxc-users] Migrating from LXC to LXD

2020-01-21 Thread Fajar A. Nugraha
On Wed, Jan 22, 2020 at 9:01 AM Michael Eager wrote: > devices: >eth0: > name: eth0 > nictype: macvlan > parent: br0 > type: nic > When I try to do the same with a CentOS 8 image, it doesn't work.

Re: [lxc-users] Howto save snapshots only to another drive? Bug?

2020-01-14 Thread Fajar A. Nugraha
On Tue, Jan 14, 2020 at 2:28 PM Jäkel, Guido wrote: > > Dear Oliver, > > I just want to mention, that with this workaround it isn't a real snapshot > anymore but may be called a "slow bullet" instead: It will take some real > time to copy the whole image and in contrast to a snapshot, it will

Re: [lxc-users] Howto save snapshots only to another drive? Bug?

2020-01-13 Thread Fajar A. Nugraha
On Mon, Jan 13, 2020 at 3:57 PM Oliver Rath wrote: > > Hi Fajar, > > its "dir": > > lxc storage show default | grep driver > driver: dir If it's dir, you could probably work around that by using bind mounts. something like rm /path/to/pool/dir/containers-snapshots <= remove the symlink first

Re: [lxc-users] Howto save snapshots only to another drive? Bug?

2020-01-12 Thread Fajar A. Nugraha
On Mon, Jan 13, 2020 at 5:01 AM Oliver Rath wrote: > > Hi list, > > Im using lxd 3.18 on ubuntu 18.04. Now i realized, that my (fast) space > of lxc-vms exhausted, so i decided to put mv my snaps to another drive > with changing the directory "containers-snapshots" into a softlink > redirecting

Re: [lxc-users] Converting network from LXC to LXD

2019-12-22 Thread Fajar A. Nugraha
On Sun, Dec 22, 2019 at 1:09 AM John Lane wrote: > > On 21/12/2019 16:51, John Lane wrote: > > > > > I can't do this: > > > > $ lxc config device set mycontainer eth0 ipv4.address 192.168.21.2/24 > >Error: Invalid devices: > > Invalid value for

Re: [lxc-users] Converting network from LXC to LXD

2019-12-20 Thread Fajar A. Nugraha
On Fri, Dec 20, 2019 at 7:08 PM John Lane wrote: > I'm struggling to find documentation explaining how to configure the > "phys" network type I use to assign a physical interface to a container > and the "veth" network type that I use to join a container to an > existing bridge. > I've looked at

Re: [lxc-users] Network Manager makes RHEL 8 and Centos 8 impossible to use as a container

2019-12-16 Thread Fajar A. Nugraha
On Tue, Dec 17, 2019 at 8:24 AM Saint Michael wrote: > > Network Manager makes RHEL 8 and Centos 8 impossible to conteinarize. Please > see that it detects a device type macvlan, when it should be really Ethernet. > nmcli connection up Ethernet0 Error: Connection activation failed: No >

Re: [lxc-users] Docker in unprivileged LXC?

2019-11-20 Thread Fajar A. Nugraha
On Wed, Nov 20, 2019 at 6:41 PM Dirk Geschke wrote: > > Hi Oliver, > > > afaik: > > > > security.nesting: "true" > > > > makes the container automatically privileged... no. it still runs using mapped unprivileged u/gid, but allows additional capabilities (e.g. overlay mounts, etc) # cat

Re: [lxc-users] Error: websocket: close 1006 (abnormal closure): unexpected EOF

2019-09-19 Thread Fajar A. Nugraha
On Fri, Sep 20, 2019 at 4:14 AM Tomasz Chmielewski wrote: > > Ubuntu 18.04, lxd installed from snap. > > Very often, a "lxc shell container" or "lxc exec container some-command" > session gets interrupted with: > > Error: websocket: close 1006 (abnormal closure): unexpected EOF > > > I suppose

Re: [lxc-users] Snashot left behind after deleting container?

2019-09-19 Thread Fajar A. Nugraha
On Wed, Sep 18, 2019 at 10:15 PM Lai Wei-Hwa wrote: > I don't see it listed when using:* lxc storage volume list* > > But it does appear to be a snapshot. How was this generated? Why is it > there? I see others that have similar naming conventions (ending in a > number string that I didn't

Re: [lxc-users] Security gain: Start Unpriviledged container as root or as regular user?

2019-08-19 Thread Fajar A. Nugraha
On Sun, Aug 18, 2019 at 5:36 PM Georg Gast wrote: > Hi, > > i use currently unprivileged lxc containers on debian buster started as > root. I use for every container a separate set of uid/gids. > > > Debian Buster uses LXC 3.1.0 > > Is in this setup any security gained, if the containers are

Re: [lxc-users] Unprivileged account(s)

2019-07-24 Thread Fajar A. Nugraha
On Thu, Jul 25, 2019 at 6:30 AM Narcis Garcia wrote: > Hello, I've been creating LXC containers in a dedicated user account. > I need to know if this is a good practice, instead of dedicating > different user account per each unprivileged container. > > It depends on what you're trying to

Re: [lxc-users] limits.memory - possible to set per group of containers?

2019-06-17 Thread Fajar A. Nugraha
On Tue, Jun 18, 2019 at 7:47 AM Tomasz Chmielewski wrote: > Let's say I have a host with 32 GB RAM. > > To make sure the host is not affected by any weird memory consumption > patterns, I've set the following in the container: > >limits.memory: 29GB > > This works quite well - where

Re: [lxc-users] LXC-3.1 - console disfunctional

2019-05-29 Thread Fajar A. Nugraha
On Wed, May 29, 2019 at 10:37 PM wrote: > Hi Oliver! > > Thanks, but I am using Debian, Buster! > > Just to see, if this depends on Buster, I created > a new container using Stretch, but it behaves the same. > > But there error at the end of the createion process: > > update-rc.d: error: cannot

Re: [lxc-users] not allowed to change kernel parameters inside container

2019-05-28 Thread Fajar A. Nugraha
On Wed, May 29, 2019 at 10:44 AM Saint Michael wrote: > The Achilles' heel is the type of CPU. I had to recompile my app once I > moved it to an older CPU. Nothing is portable 100%. > I guess nothing allows you to get rid of the developer at the end of the > day. > If you compile it yourself,

Re: [lxc-users] not allowed to change kernel parameters inside container

2019-05-28 Thread Fajar A. Nugraha
On Tue, May 28, 2019 at 8:18 PM Saint Michael wrote: > Thanks for the F grade. > In telecommunications, there is a special kind of software apps called > switches, which actually involve dozens of apps, scripts, etc. That kind of > complexity is only packageable in a container. > It's a matter

Re: [lxc-users] not allowed to change kernel parameters inside container

2019-05-27 Thread Fajar A. Nugraha
On Tue, May 28, 2019 at 12:39 PM Saint Michael wrote: > This > "host and container can't have services run on the same port (e.g. if you > want sshd on both host and container, you need to change the listening port > for one of them)" > is untrue. > each container in my case has a different IP

Re: [lxc-users] not allowed to change kernel parameters inside container

2019-05-27 Thread Fajar A. Nugraha
On Mon, May 27, 2019 at 8:11 PM Saint Michael wrote: > I thought I did start the containers as privileged: > > lxc.include = /usr/share/lxc/config/ubuntu.common.conf > lxc.mount.auto= > lxc.mount.auto=proc:rw sys:rw cgroup:rw > lxc.apparmor.profile=unconfined > lxc.tty.max = 10 > lxc.pty.max =

Re: [lxc-users] not allowed to change kernel parameters inside container

2019-05-26 Thread Fajar A. Nugraha
On Sun, May 26, 2019 at 9:18 AM Saint Michael wrote: > I am fine with having full interaction with the host. The host does not do > anything, it is like a glove for my app, which uses UDP very intensely, > like 500 Mbits per second. I need to fine-tune all its parameters. > > > > On Sat, May 25,

Re: [lxc-users] Looking for LXD Container with AWS CDN Experience?

2019-03-28 Thread Fajar A. Nugraha
On Mon, Mar 25, 2019 at 3:31 AM Ray Jender wrote: > If there is anyone experienced with using the Amazon Cloudfront with an > LXD container, I could really use a little help! > > Please let me know. > > Did you also wrote this?

Re: [lxc-users] future of lxc/lxd? snap?

2019-02-25 Thread Fajar A. Nugraha
On Mon, Feb 25, 2019 at 5:20 PM Stéphane Graber wrote: > snapd + LXD work fine on CentOS 7, it's even in our CI environment, so > presumably the same steps should work on RHEL 7. > > Awesome ! > In the past I've built private RPMs for lxd on centos. It became a hassle > though as (for example)

Re: [lxc-users] future of lxc/lxd? snap?

2019-02-25 Thread Fajar A. Nugraha
On Mon, Feb 25, 2019 at 3:15 PM Harald Dunkel wrote: > On 2/25/19 4:52 AM, Fajar A. Nugraha wrote: > > > > snapcraft.io <http://snapcraft.io/> is also owned by Canonical. > > > > By using lxd snap, they can easly have lxd running on any distro that > a

Re: [lxc-users] future of lxc/lxd? snap?

2019-02-24 Thread Fajar A. Nugraha
On Sat, Feb 23, 2019 at 9:46 PM Richard Hector wrote: > Hi all, > > I see that lxd in ubuntu cosmic and disco is a transitional package for > snap - I see that lxd can be used for snap packages, but they're not the > same thing, right? > >

Re: [lxc-users] lxd access from host to container rootfs

2018-12-09 Thread Fajar A. Nugraha
On Wed, Dec 5, 2018 at 9:03 PM Ingo Baab wrote: > Hello All, > how can I access the LXD/LXC containers rootfs from the host system? > (if I am using ubuntu18.04 with snap lxc --version 3.7 on loopback-ZFS) > > On other (real ZFS-based and U16.04) server I can access: > >

Re: [lxc-users] Does cpu cgroup has been enabled in lxc/lxd

2018-11-02 Thread Fajar A. Nugraha
On Fri, Nov 2, 2018 at 8:44 AM, kemi wrote: > > thx for your question. > In our case, our customers want to run android games within containers on > cloud. > It might be possible for you to adjust https://anbox.io/ to run on lxd instead of lxc. YMMV. There are two problems we have known. > The

Re: [lxc-users] Does cpu cgroup has been enabled in lxc/lxd

2018-11-01 Thread Fajar A. Nugraha
On Thu, Nov 1, 2018 at 3:04 PM, kemi wrote: > > The reason why I have not tried it is there is no available android image > provided on existed > images server for LXD container. Do you know something about that? > I don't believe anybody has succesfully run android in lxd yet (sucess as in

Re: [lxc-users] Does cpu cgroup has been enabled in lxc/lxd

2018-11-01 Thread Fajar A. Nugraha
On Thu, Nov 1, 2018 at 2:16 PM, kemi wrote: > > > On 2018/11/1 下午2:53, Fajar A. Nugraha wrote: > > On Thu, Nov 1, 2018 at 1:38 PM, kemi wrote: > > > >>>> g) and h) read files from /proc, not cgroup. You need lxcfs. You > should &g

Re: [lxc-users] Does cpu cgroup has been enabled in lxc/lxd

2018-11-01 Thread Fajar A. Nugraha
On Thu, Nov 1, 2018 at 1:38 PM, kemi wrote: > >> g) and h) read files from /proc, not cgroup. You need lxcfs. You should > >> already have that on ubuntu though. > >> > >> > > /proc/cpuinfo also matches the expected result. > However, it seems that sysfs in container still shares with host /sys

Re: [lxc-users] Does cpu cgroup has been enabled in lxc/lxd

2018-10-31 Thread Fajar A. Nugraha
On Thu, Nov 1, 2018 at 8:55 AM, kemi wrote: > Hi, Everyone >I am new comer of LXC/LXD community, and want to run a container on a > limited cpu set. > > The followings are my steps: > a) lxd init > b) lxc launch Ubuntu:18.04 first > c) lxc stop first > d) lxc config set first

Re: [lxc-users] lxd under stretch

2018-09-25 Thread Fajar A. Nugraha
On Tue, Sep 25, 2018 at 1:34 AM, Pierre Couderc wrote: > > > On 09/24/2018 10:20 AM, Andrey Repin wrote: > >> >> If you are asking such questions, you definitely should not build anything >> yourself. >> >> Thank you for you efficient answer that I definitely intend not to > follow ;) > Maybe

Re: [lxc-users] Error: failed to begin transaction: database is locked

2018-09-12 Thread Fajar A. Nugraha
On Wed, Sep 12, 2018 at 9:33 PM, Kees Bakker wrote: > Hey, > > This with a LXD/LXC on a Ubuntu 18.04 server. Storage is done > with LVM. It was installed as a cluster with just one node. > It was also added as remote for three other LXD servers (all Ubuntu 16.04 > and LXD 2.0.x). These old

Re: [lxc-users] How to recover from ERROR state

2018-09-12 Thread Fajar A. Nugraha
On Wed, Sep 12, 2018 at 4:08 PM, Kees Bakker wrote: > On 12-09-18 10:51, Fajar A. Nugraha wrote: > > On Wed, Sep 12, 2018 at 3:14 PM, Kees Bakker wrote: > >> On 11-09-18 21:56, Andrey Repin wrote: >> > Greetings, Kees Bakker! >> > >> >>

Re: [lxc-users] How to recover from ERROR state

2018-09-12 Thread Fajar A. Nugraha
On Wed, Sep 12, 2018 at 3:14 PM, Kees Bakker wrote: > On 11-09-18 21:56, Andrey Repin wrote: > > Greetings, Kees Bakker! > > > >> ii lxc-common 2.0.8-0ubuntu1~16.04.2 amd64Linux > Containers userspace tools (common tools) > >> ii lxcfs 2.0.8-0ubuntu1~16.04.2 amd64

Re: [lxc-users] Where is stored the list of remote lxds ?

2018-08-25 Thread Fajar A. Nugraha
On Sat, Aug 25, 2018 at 5:40 PM, Pierre Couderc wrote: > Paying with lxd to understand it more (and because of a mysterious > failure), I decide to reinit the whole lxd, as I delete the full > /var/lib/lxd and excutes lxd init. > > So I am surprised that : > > lxd remote list > > finds me old

Re: [lxc-users] How to copy "manually" a container ?

2018-08-23 Thread Fajar A. Nugraha
On Thu, Aug 23, 2018 at 2:38 PM, Pierre Couderc wrote: > On 08/23/2018 09:24 AM, Fajar A. Nugraha wrote: > > On Thu, Aug 23, 2018 at 2:07 PM, Pierre Couderc wrote: > >> On 08/23/2018 07:37 AM, Tamas Papp wrote: >> >>> >>> On 08/23/2018 05:36 AM, Pierre

Re: [lxc-users] How to copy "manually" a container ?

2018-08-23 Thread Fajar A. Nugraha
On Thu, Aug 23, 2018 at 2:07 PM, Pierre Couderc wrote: > On 08/23/2018 07:37 AM, Tamas Papp wrote: > >> >> On 08/23/2018 05:36 AM, Pierre Couderc wrote: >> >>> If for any reason, "lxc copy" does not work, is it enough to copy >>> (rsync) /var/lib/lxd/containers/ to another lxd on another

Re: [lxc-users] bridged device's name

2018-08-20 Thread Fajar A. Nugraha
On Tue, Aug 21, 2018 at 8:40 AM, Mike Wright wrote: > Hi all, > > Is there a way to set a network device's host side name? > > e.g. with lxc style configs: > > #myContainer > lxc.net.0.type = veth > lxc.net.0.veth.pair = host-side-name > lxc.net.0.link = myBridge > > Are you asking the

Re: [lxc-users] Containers won't start under stretch-backport kernel reboot

2018-08-14 Thread Fajar A. Nugraha
On Wed, Aug 15, 2018 at 9:52 AM, Tony Lewis wrote: > Aug 15 11:40:50 server snap[6761]: lxd: error while loading shared > libraries: liblxc.so.1: cannot open shared object file: No such file or > directory > This is something to follow up The library is present in what looks to be the right

Re: [lxc-users] Containers won't start under stretch-backport kernel reboot

2018-08-14 Thread Fajar A. Nugraha
On Tue, Aug 14, 2018 at 1:54 PM, Tony Lewis wrote: > Apologies in advance for the bump, but does anyone have an insights on > this? > > Did you install lxd before using source instead of snap? => lxd.service loaded active exitedLSB: Container hypervisor based on LXC You shouldn't have that

Re: [lxc-users] lxc build failure

2018-08-11 Thread Fajar A. Nugraha
On Sat, Aug 11, 2018 at 10:05 PM, Fajar A. Nugraha wrote: > On Sat, Aug 11, 2018 at 1:37 PM, Pierre Couderc wrote: > >> Trying to build lxd from sources, I get a message about sqlite3 missing, >> and an invite to "make deps". >> >> But it fails too wi

Re: [lxc-users] lxc build failure

2018-08-11 Thread Fajar A. Nugraha
On Sat, Aug 11, 2018 at 1:37 PM, Pierre Couderc wrote: > Trying to build lxd from sources, I get a message about sqlite3 missing, > and an invite to "make deps". > > But it fails too with : > > > No package 'sqlite3' found > > Consider adjusting the PKG_CONFIG_PATH environment variable if you >

Re: [lxc-users] LXC container and Systemd

2018-08-10 Thread Fajar A. Nugraha
On Fri, Aug 10, 2018 at 5:12 PM, Goran wrote: > Your test-asuser.service works as intended. If I change the user and > group to grafana it shows the same problems. > > # id grafana > uid=207(grafana) gid=207(grafana) groups=207(grafana) > > # cat /etc/passwd > ... >

Re: [lxc-users] LXC container and Systemd

2018-08-10 Thread Fajar A. Nugraha
On Fri, Aug 10, 2018 at 4:38 PM, Goran wrote: > Always the same behavior, if the binary is executed as a user > different from root, systemd does not find the binary. > > In this case > > # which bash > /usr/bin/bash > > can't be found by systemd. ExecStart=whatsoever does not work. It > doesn't

Re: [lxc-users] LXD move container to another pool ?

2018-08-09 Thread Fajar A. Nugraha
On Thu, Aug 9, 2018 at 7:57 PM, Pierre Couderc wrote: > > On 08/09/2018 11:30 AM, Fajar A. Nugraha wrote: > > > Basically you'd just need to copy /var/lib/lxd and whatever storage > backend you use (I use zfs), and then copy them back later. Since I also > pu

Re: [lxc-users] LXC container and Systemd

2018-08-09 Thread Fajar A. Nugraha
On Thu, Aug 9, 2018 at 8:11 PM, Goran wrote: > I did as you told. What I can say is that the user/group directive are > the problem. > > With this config it works: > > Now we're getting somehwere :D > [Unit] > Description=Grafana service > After=network.target > > [Service] > # User=grafana

Re: [lxc-users] LXC container and Systemd

2018-08-09 Thread Fajar A. Nugraha
On Tue, Aug 7, 2018 at 11:13 PM, Goran wrote: > I'm starting Grafana on top of Arch Linux without problem. But when I > install Grafana into an Arch Linux LXC container on top of Arch Linux > OS I can't start it. > > The error is: > > systemd[24509]: grafana.service: Failed to determine user

Re: [lxc-users] Convert virtual machine to LXC container

2018-08-08 Thread Fajar A. Nugraha
Aug 9, 2018 at 10:59 AM, Saint Michael wrote: > LXD does not support lxc-attach? > I thought that LXD was a superset of LXC, that added on top of it. > Maybe somebody care to explain how LXC and LXD compare. > > > On Wed, Aug 8, 2018 at 11:21 PM Fajar A. Nugraha wrote: > >

Re: [lxc-users] Convert virtual machine to LXC container

2018-08-08 Thread Fajar A. Nugraha
I've converted (manually) some lxc containers to lxd and back in the past. IIRC the biggest difference was that lxd does not need to output anything to console, while lxc needs it (e.g. for lxc-attach). Depending on what container distro and version you use, it might not matter (e.g. it should

Re: [lxc-users] unprivileged containers and databases

2018-08-07 Thread Fajar A. Nugraha
Which distro, and how did you install it? Using ubuntu 18.04.1 host, bundled lxd 3.0.1-0ubuntu1~18.04.1, I was able to start mariadb (10.1 bundled in ubuntu, as well as 10.2 and 10.3 from https://downloads.mariadb.org/mariadb/repositories/) in unpriv lxd container just fine. IIRC on openvpn its

Re: [lxc-users] What is the state of the art for lxd and wifi ?

2018-07-23 Thread Fajar A. Nugraha
On Mon, Jul 23, 2018 at 5:33 PM, Pierre Couderc wrote: > > On 07/23/2018 12:12 PM, Fajar A. Nugraha wrote: > > Relevant to all VM-like in general (including lxd, kvm and virtualbox): > - with the default bridged setup (on lxd this is lxdbr0), VMs/containers > c

Re: [lxc-users] What is the state of the art for lxd and wifi ?

2018-07-23 Thread Fajar A. Nugraha
On Mon, Jul 23, 2018 at 5:08 PM, Pierre Couderc wrote: > Where can I find a howto for lxd on a an ultramobile with wifi only ? > > I find some posts aged 2014 and more modern posts saying it is not > possible with wifi. > > I want to install many containers accessing internet, or being acessed >

Re: [lxc-users] lxd 3.0.0: What is a "managed" network? Only managed networks can be modified.

2018-05-06 Thread Fajar A. Nugraha
On Mon, May 7, 2018 at 2:10 AM, Gaétan QUENTIN wrote: > > lxc network list > +-+--+-+-+-+ > | NAME | TYPE | MANAGED | DESCRIPTION | USED BY | >

Re: [lxc-users] bionic image not getting IPv4 address

2018-05-03 Thread Fajar A. Nugraha
On Thu, May 3, 2018 at 8:09 PM, David Favor wrote: > This is tricky... Netplan forced abuse is similar to systemd... No one > likes systemd + it works abysmally + it was crammed down everyone's > throat. > > It appears Netplan will be the same. > > Eventually some update

Re: [lxc-users] bionic image not getting IPv4 address

2018-05-03 Thread Fajar A. Nugraha
On Thu, May 3, 2018 at 7:57 PM, Tomasz Chmielewski wrote: > Indeed, I can confirm it's some netplan-related issue with > /etc/netplan/10-lxc.yaml. > > Working version for bionic containers set up before 2018-May-02: > > network: > ethernets: > eth0: {dhcp4: true} >

Re: [lxc-users] bionic image not getting IPv4 address

2018-05-03 Thread Fajar A. Nugraha
On Thu, May 3, 2018 at 1:28 PM, Kees Bos wrote: > On Thu, 2018-05-03 at 08:09 +0200, Kees Bos wrote: >> On Thu, 2018-05-03 at 12:58 +0900, Tomasz Chmielewski wrote: >> > >> > Reproducing is easy: >> > >> > # lxc launch images:ubuntu/bionic/amd64 bionic-broken-dhcp >> > >>

Re: [lxc-users] bionic image not getting IPv4 address

2018-05-03 Thread Fajar A. Nugraha
On Thu, May 3, 2018 at 10:14 AM, David Favor wrote: > Be aware there is a bug in Bionic packaging, so if you upgrade > machine level OS from any previous OS version to Bionic, LXD > networking becomes broken... so badly... no Ubuntu or LXD developer > has figured out a fix.

Re: [lxc-users] authentication in containers jacked-up!

2018-04-09 Thread Fajar A. Nugraha
On Thu, Mar 29, 2018 at 8:22 PM, Ray Jender wrote: > ray@ container 2:/etc$ sudo visudo > > sudo: no tty present and no askpass program specified > Try 'sudo -S visudo' -- Fajar ___ lxc-users mailing list

Re: [lxc-users] dynamic cgroup memory limit

2018-04-01 Thread Fajar A. Nugraha
On Sat, Mar 31, 2018 at 9:43 PM, Tian-Jian Wu wrote: > We are developers of project clondroid (https://github.com/clondroid) > Our android porting lxc tools are at > https://github.com/clondroid/lxc-for-Android-7.1.2. > This command 'lxc config set my-container limits.memory

Re: [lxc-users] Limit network bandwidth to LXC containers

2018-03-14 Thread Fajar A. Nugraha
On Thu, Mar 15, 2018 at 3:06 AM, Angel Lopez wrote: > Hi, > > I need to limit the network bandwidth available to each LXC container using > cgroup's net_cls.classid feature. Each LXC container would have its own > classid value in such a way that all packets from containers

Re: [lxc-users] container root unable to setcap in container

2018-03-09 Thread Fajar A. Nugraha
On Fri, Mar 9, 2018 at 5:09 PM, Michael Johnson wrote: > Hi All! > > I have noticed that a container's root user is unable to modify the > capabilities of a root-owned file in the container. > > For example: > setcap cap_net_raw=ep /bin/ping > returns: > Failed to set

Re: [lxc-users] Upgrading host and containers : in which order ?

2018-03-08 Thread Fajar A. Nugraha
On Thu, Mar 8, 2018 at 5:56 PM, phep wrote: > Hi, > > Pretty much every thing's in the subject line : we've got a host running > Debian Jessie and LXC 1.0 with a handful of containers in the same Debian > version that we all need to upgrade to Debian Stretch with LXC 2.0. By

Re: [lxc-users] LXC copy snapshots only to remote?

2018-03-07 Thread Fajar A. Nugraha
On Thu, Mar 8, 2018 at 1:49 AM, Lai Wei-Hwa wrote: > Thanks Fajar, > > I'm more interested in if I'm right or wrong and why that's the case. > > Incremental snapshot support is in LXD 3.0 but I'm asking in relation to > LXC, not LXD. And I'm really looking to clear up my

Re: [lxc-users] LXC copy snapshots only to remote?

2018-03-07 Thread Fajar A. Nugraha
On Thu, Mar 8, 2018 at 12:03 AM, Lai Wei-Hwa wrote: > Hi Everyone, > > I'm probably not fully grasping how LXC containers/snapshotting works, but > why isn't the following possible? > > *Host* *Container* > *Monday* > *Tuesday* > *Wed* > *Thurs* > H1 > C1 (fresh Ubuntu) > SA

Re: [lxc-users] LXC container isolation with iptables?

2018-03-04 Thread Fajar A. Nugraha
On Sun, Mar 4, 2018 at 5:27 PM, Marat Khalili wrote: > On 04/03/18 02:26, Steven Spencer wrote: > > Honestly, unless I'm spinning up a container on my local desktop, I always > use the routed method. Because our organization always thinks of a container > as a separate machine, it

Re: [lxc-users] LXC container isolation with iptables?

2018-02-27 Thread Fajar A. Nugraha
On Wed, Feb 28, 2018 at 12:21 AM, bkw - lxc-user wrote: > I have an LXC host. On that host, there are several unprivileged > containers. All containers and the host are on the same subnet, shared via > bridge interface br0. > > If container A (IP address 192.168.1.4)

Re: [lxc-users] User Mode Linux within a Linux Container

2018-01-30 Thread Fajar A. Nugraha
On Wed, Jan 31, 2018 at 2:54 AM, Pablo Pessolani wrote: > Does anybody has run User Mode Linux (UML) within a Linux Container? > > And several UMLs within several Containers? (one UML by Container) > > Is there any limitation so that this can not be done? If you're

Re: [lxc-users] lxcfs removed by accident, how to recover?

2018-01-30 Thread Fajar A. Nugraha
On Tue, Jan 30, 2018 at 7:34 PM, Harald Dunkel wrote: > Hi folks, > > I have removed the lxcfs package by accident, while the containers > are still running. > Is there some way to recover without restaring the containers? I'm pretty sure the answer is "no". Even lxcfs

Re: [lxc-users] storage pool on zfs root not possible ?

2017-12-12 Thread Fajar A. Nugraha
Sorry, hit send to soon. Here's the correctly-edited response On Wed, Nov 22, 2017 at 5:36 PM, supp...@translators.at < supp...@translators.at> wrote: > > > hi folks, > > have a zfs-root-raid system with > dedicated zfsroot/opt partitioned. > upon zfs-root running

Re: [lxc-users] storage pool on zfs root not possible ?

2017-12-12 Thread Fajar A. Nugraha
On Wed, Nov 22, 2017 at 5:36 PM, supp...@translators.at < supp...@translators.at> wrote: > > > hi folks, > > have a zfs-root-raid system with > dedicated zfsroot/opt partitioned. > upon zfs-root running ubuntu 16.04 lts. > already installed snap-lxd. > >

Re: [lxc-users] Trouble with automounting /dev/shm

2017-11-24 Thread Fajar A. Nugraha
On Sat, Nov 25, 2017 at 5:59 AM, Pavol Cupka wrote: > can you have multiline raw.lxc ? > > Yes. See https://github.com/lxc/lxd/issues/2343#issuecomment-245102205 for example -- Fajar ___ lxc-users mailing list

Re: [lxc-users] Using a mounted drive to handle storage pool

2017-11-21 Thread Fajar A. Nugraha
On Wed, Nov 22, 2017 at 1:37 AM, Lai Wei-Hwa wrote: > I've currently migrated LXD from canonical PPA to Snap. > > I have 2 RAIDS: > >- /dev/sda - ext4 (this is root device) >- /dev/sdb - brtfs (where I want my pool to be with the containers and >snapshots) > >

Re: [lxc-users] TTY issue

2017-11-16 Thread Fajar A. Nugraha
On Thu, Nov 16, 2017 at 10:50 PM, Saint Michael wrote: > The issue is with fuse, that is why I keep > lxc.autodev=0 > if I do not, if I set it to 1, then fuse does not mount inside a > container. I need fuse, for I mount an FTP server inside the container. > So I am caught

Re: [lxc-users] TTY issue

2017-11-16 Thread Fajar A. Nugraha
On Thu, Nov 16, 2017 at 10:04 PM, Saint Michael wrote: > I missfired. > But I found the culprit, it is > lxc.autodev = 0 > > if I use > lxc.autodev = 1 > the issue does not happens > Can somebodu shed any light on the ramifications of this? > Try

Re: [lxc-users] TTY issue

2017-11-15 Thread Fajar A. Nugraha
On Thu, Nov 16, 2017 at 10:04 AM, Saint Michael wrote: > I did apply all suggested solutions that you found googling. None works. > I do not use LXD, just plain LXC. > lxc-start --version > 2.0.9 > lsb_release -a > No LSB modules are available. > Distributor ID: Ubuntu >

Re: [lxc-users] Number of core for a container

2017-11-10 Thread Fajar A. Nugraha
Disclaimer: I no longer use lxc. Mostly lxd nowadays. I can point you to some documentation on the web though, hopefully that helps On Fri, Nov 10, 2017 at 7:29 PM, Thouraya TH wrote: > Hi all, > > I have used this command to fix cpu cores on which we have set running >

Re: [lxc-users] Ubuntu bionic beaver 18.04 (pre-alpha?) and lxc (experiments)

2017-11-08 Thread Fajar A. Nugraha
On Thu, Nov 9, 2017 at 7:49 AM, Adrian Pepper wrote: > I installed Ubuntu 18.04 in a virtualbox, and then installed lxc (lxc > 2.1.1) > > ii lxc1 2.1.1-0ubuntu1 amd64Linux Containers userspace > tools > > > I then created an 18.04 container on the

Re: [lxc-users] Is there a reference manual about LXD ?

2017-10-20 Thread Fajar A. Nugraha
On Sat, Oct 21, 2017 at 7:34 AM, Pierre Couderc wrote: > Sorry, I have not fount it. > > I have installed LXD on stretch following Stéphane > https://stgraber.org/2017/01/18/lxd-on-debian. > > Fine ! an infinite progress after my successful install of lxc on jessie, > it

Re: [lxc-users] How properly to find what consumes memory inside the container.

2017-10-11 Thread Fajar A. Nugraha
On Tue, Sep 19, 2017 at 11:20 AM, Ivan Kurnosov wrote: > > But if I clear the system caches on the host > > echo 3 > /proc/sys/vm/drop_caches > > > the container memory consumption drops to the expected <100mb. > > So the question, how to monitor the memory consumption from the

Re: [lxc-users] Filtering container traffic with iptables on host

2017-09-29 Thread Fajar A. Nugraha
On Fri, Sep 29, 2017 at 7:23 PM, Björn Fischer wrote: > root@drax:/root# lxc shell moonraker > Wow # lxc | egrep 'shell|exec' exec Execute commands in containers 'shell' is not even in the lxc command line help yet :) Thanks for letting me know

Re: [lxc-users] Marking running containers as emphermial

2017-09-12 Thread Fajar A. Nugraha
On Tue, Sep 12, 2017 at 3:16 AM, Dave Smith wrote: > I have an application that I am running as a single process in an lxc > container . The process is serving websocket requests from an upstream > proxy. What I would like to do is when we do an update , we launch a new

Re: [lxc-users] Lxc list - permission denied

2017-09-08 Thread Fajar A. Nugraha
On Sun, Sep 3, 2017 at 9:18 AM, Eric Wolf <19w...@gmail.com> wrote: > 19wolf@Nephele:~$ lxc list >>Permission denied, are you in the lxd group? > 19wolf@Nephele:~$ sudo adduser 19wolf lxd >>The user `19wolf' is already a member of `lxd'. > 19wolf@Nephele:~$ lxc list >>Permission denied, are you in

Re: [lxc-users] Diff between two directory (rootFS) of two containers

2017-09-03 Thread Fajar A. Nugraha
On Sat, Sep 2, 2017 at 4:56 PM, Thouraya TH wrote: > Hi all, > > Please, i have created two containers (Ubuntu). > Is the two rootFS directory are similar ? Is it the same content ? Probably. Giving more details (as in, why are you asking this? are you doing a school

Re: [lxc-users] lxd host can not access container via domain

2017-09-03 Thread Fajar A. Nugraha
On Sat, Sep 2, 2017 at 9:02 AM, Benjamin Asbach wrote: > Hi there, > > I've some problems with connecting to my containers via my public domain > from the host itself. I'm using bridged network by lxc network. The setup > looks like this > > remote -> domain.com -> host ->

Re: [lxc-users] lxc config preventing mysql

2017-08-20 Thread Fajar A. Nugraha
On Fri, Aug 11, 2017 at 3:27 AM, Jake Black wrote: > This is how the container is created if we need to mount nfs to it. > > lxc launch "${IMAGE}" "${NAME}" > lxc config set ${NAME} security.privileged true > lxc config set ${NAME} raw.apparmor 'mount,' Thanks for the info, I

  1   2   3   4   5   6   >