From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 75CB8745AC for ; Mon, 19 Apr 2021 02:52:59 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 62438EBEA for ; Mon, 19 Apr 2021 02:52:29 +0200 (CEST) Received: from mail-pj1-x102c.google.com (mail-pj1-x102c.google.com [IPv6:2607:f8b0:4864:20::102c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with ESMTPS id 36E32EBDB for ; Mon, 19 Apr 2021 02:52:25 +0200 (CEST) Received: by mail-pj1-x102c.google.com with SMTP id nk8so3778608pjb.3 for ; Sun, 18 Apr 2021 17:52:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=to:from:subject:message-id:date:user-agent:mime-version :content-transfer-encoding:content-language; bh=8Uy2A6L9Tfqbt5H+/J/FcFnNNJqnzeI0WxAyyeHGWb4=; b=BXmSF/7HGRBxGSyr4GHvnXHasamnyk2svTyohRrrP1XygjNYDi5ZNadZcqapJw7Ru4 EVdhVuAYNAa9WlgBdlo8EEoxQg/lA9++yVYMsYX3PyAl/V3vGPksvRBvR7T8JrZfgmCZ 219bOR4nRm/tn8LAK95BTaNkkcrk1FW13YEd6WS2bq+dwcL40aQclgLIAM98u3xzDYTV 37o7c5KePUqxdWHZopRzBL4kHSkhiAIpGNVp4E63mBHsZaSD/7SAw7bUKodtuZiyCfS+ fr+yxiHtIWuOihS1ai92Ux/IkmKw0XpcPyuN84ok/YADDxQuFUHvLRHY3HtteOETgIo6 K++g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:from:subject:message-id:date:user-agent :mime-version:content-transfer-encoding:content-language; bh=8Uy2A6L9Tfqbt5H+/J/FcFnNNJqnzeI0WxAyyeHGWb4=; b=FOClpiLCvENR8qvffA1IfOgh0Dv9oE09/Pb75QyEiVUx7sgiNKhu9FyDkFtbjTX1K5 dKOHHeM8irO8qondpLrPtWhP4bfKjvxWitpC2uXkB62gumMtj+lI0uVWdgUbXY3CUEGr kDYllquS+Q8+DPFQn6CWPi79oN6f0aiF0Esj94UAC9v6EKApjZSYOGiaGYrBbONkTEb1 uDpSEzxxCrq4middBxobqwtbd1mFlxn9PffbYxeLc3NBxxmdFS/Omh+tgFSIevEvxRrt +23Y6JeSzv2xWDPV6SjEvHOqaj2PtfTGGJ7SN/UmCs9AU126SYIJIxl9ieAfgnFgisnk qSRg== X-Gm-Message-State: AOAM5302uUWz+keV0Czjiqfe8XgZ8x7cxc/nnJDcq7n1Usk7mJCRIMFi PLfDz00XkzAm58Go/Qk3hFNMfdPPnSFPaw== X-Google-Smtp-Source: ABdhPJzDMdLrtYO2cQ7KSGC6njmAW9sMCWv/xl6fnBPdBFN7pVnyt47Wb41BRax06ROqGrkbuXxXrg== X-Received: by 2002:a17:902:b602:b029:e6:cabb:10b9 with SMTP id b2-20020a170902b602b02900e6cabb10b9mr20291174pls.47.1618793536767; Sun, 18 Apr 2021 17:52:16 -0700 (PDT) Received: from [192.168.1.125] (167-179-176-9.a7b3b0.bne.nbn.aussiebb.net. [167.179.176.9]) by smtp.gmail.com with ESMTPSA id d21sm12336796pjx.24.2021.04.18.17.52.14 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 18 Apr 2021 17:52:15 -0700 (PDT) To: pve-user@lists.proxmox.com From: Lindsay Mathieson Message-ID: Date: Mon, 19 Apr 2021 10:52:09 +1000 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.9.1 MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Content-Language: en-US X-SPAM-LEVEL: Spam detection results: 0 AWL 0.038 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Subject: [PVE-User] unpriviliged lxc uid/gid mappings X-BeenThere: pve-user@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox VE user list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Apr 2021 00:52:59 -0000 I must say, I find the subject very confusing and difficult to parse. It seems very difficult to setup with multiple user and container mappings to maintain - I just setup 4 containers with 4 bind mounts each and after a lot of fiddling, got them working, but I'm not confident on maintenance for the future. I had to give up on the container that needed access to 2 USB tuners and a Intel QuickSync GPU (vaapi), ended up running that container privileged. Is there any plans to simplify it for the future? I found the LXD (4.0?) system of raw.idmap settings much easier to setup, I was able to generically script that for containers. -- Lindsay