public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
* [pve-devel] [PATCH container/manager 0/4] restrict privileged containers
@ 2025-07-30 15:00 Fabian Grünbichler
  2025-07-30 15:00 ` [pve-devel] [PATCH container 1/3] api: create: default to unprivileged containers Fabian Grünbichler
                   ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Fabian Grünbichler @ 2025-07-30 15:00 UTC (permalink / raw)
  To: pve-devel

this series
- defaults to unprivileged containers in the backend (already the
  default in the UI for a while)
- requires Sys.Modify when creating a new privileged container, or
  converting and existing unprivileged one to a privileged one via
  in-place restore

pve-container technically breaks old pve-manager, insofar as privileged
container creation via the UI is not honored.

pve-container:

Fabian Grünbichler (3):
  api: create: default to unprivileged containers
  create/restore: require Sys.Modify for privileged containers
  migration: require Sys.Modify for incoming privileged containers

 src/PVE/API2/LXC.pm | 21 ++++++++++++++-------
 1 file changed, 14 insertions(+), 7 deletions(-)

pve-manager:

Fabian Grünbichler (1):
  lxc: create: always submit unprivileged field

 www/manager6/lxc/CreateWizard.js | 1 +
 1 file changed, 1 insertion(+)

-- 
2.39.5



_______________________________________________
pve-devel mailing list
pve-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2025-07-30 23:59 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-07-30 15:00 [pve-devel] [PATCH container/manager 0/4] restrict privileged containers Fabian Grünbichler
2025-07-30 15:00 ` [pve-devel] [PATCH container 1/3] api: create: default to unprivileged containers Fabian Grünbichler
2025-07-30 23:59   ` [pve-devel] applied: " Thomas Lamprecht
2025-07-30 15:00 ` [pve-devel] [PATCH container 2/3] create/restore: require Sys.Modify for privileged containers Fabian Grünbichler
2025-07-30 23:59   ` [pve-devel] applied: " Thomas Lamprecht
2025-07-30 15:00 ` [pve-devel] [PATCH container 3/3] migration: require Sys.Modify for incoming " Fabian Grünbichler
2025-07-30 23:59   ` [pve-devel] applied: " Thomas Lamprecht
2025-07-30 15:00 ` [pve-devel] [PATCH manager 1/1] lxc: create: always submit unprivileged field Fabian Grünbichler
2025-07-30 23:21   ` [pve-devel] applied: " Thomas Lamprecht

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal