标签归档:lxc

LXC 热载入设备文件

下面以向运行中的 LXC 容器注入 /dev/vhost-net 为例讲解。

有两种思路:临时注入(容器重启后失效)和永久配置(写入配置)。有时无法重启 lxc 容器,希望配置生效,就可以用临时注入热载入,在写入配置,这样现在就可以用,下次重启后载入配置就不用热载入了。下面介绍方法:

临时注入

(容器运行中,立即生效)

步骤 1:在宿主机上确认设备号

ls -l /dev/vhost-net
# crw-rw-rw- 1 root kvm 10, 238 ... /dev/vhost-net

主设备号通常是 10,次设备号常见为 238(以你机器输出为准)。

如果没有该设备,先加载模块:

modprobe vhost_net

步骤 2:在容器的 devices cgroup 中放行该设备

cgroup v1:

lxc-cgroup -n <容器名> devices.allow "c 10:238 rwm"

cgroup v2(现代发行版默认)没有 devices.allow 文件,设备控制基于 eBPF,lxc-cgroup 一般无法这样动态修改。此时建议改用下面的”永久配置 + 重启”。

步骤 3:在容器内创建设备节点

lxc-attach -n <容器名> -- mknod -m 666 /dev/vhost-net c 10 238

或直接去容器里执行后面的命令即可。

注意:如果是非特权容器,容器内 mknod 通常会被拒绝(用户命名空间中没有 CAP_MKNOD),此时需要用 bind mount 方式或永久配置。

替代:直接 bind mount 设备文件(不需要 mknod)

# 找到容器的 rootfs 路径后,在宿主机上创建目标文件并 bind mount
touch /var/lib/lxc/<容器名>/rootfs/dev/vhost-net
mount --bind /dev/vhost-net /var/lib/lxc/<容器名>/rootfs/dev/vhost-net

(还需要 cgroup 放行,否则容器里访问会得到 Operation not permitted。)

永久配置

编辑 /var/lib/lxc/<容器名>/config(或 ~/.local/share/lxc/...):

# cgroup v1
lxc.cgroup.devices.allow = c 10:238 rwm

# cgroup v2
lxc.cgroup2.devices.allow = c 10:238 rwm

# 自动挂载设备节点
lxc.mount.entry = /dev/vhost-net dev/vhost-net none bind,create=file 0 0

然后重启容器。

lxc 使用 chronyc 构建 ntp 服务

lxc 启动 chronyd 是无法直接启动的,因为用到了很多未授权的权限。

TL;DR

lxc与宿主机共用内核,因此时间也是共用的,无需同步。如果你想构建一个 ntp 服务,不需要同步时间,可以像下面这样做:

$ sudo systemctl edit chrony
# 新增以下内容:
[Service]
User=
Group=
ExecStart=
ExecStart=/usr/sbin/chronyd -F 1 -x

这些配置会覆写默认的 chrony 后台服务参数,启动 chronyd 时加 -x,禁用步进/微调系统时钟,这样即使没有 CAP_SYS_TIME 也能跑起来。 上面两行 User 和 Group 这样 chronyd 会以 root 启动,然后按照 /etc/chrony/chrony.conf 里的 user chrony 自动降权运行,这是官方推荐方式。

这样配置后 chrony 的服务就可以启动了,可以对外发布 ntp 服务。

Refs

确认当前终端是否运行在 LXC 容器

要确定当前运行的系统是否在 LXC 容器中,可以检查特定的环境变量和文件。以下是一种方法,通过查看 /proc/1/environ 文件来判断:

在终端中运行以下命令:

cat /proc/1/environ | tr '\0' '\n' | grep '^container='

观察输出的内容。如果输出包含 container=lxc,则表示您当前正在 LXC 容器内运行。例如:

container=lxc

如果输出为空,那么您可能不在 LXC 容器内运行。

另一种方法是检查 /proc/1/cgroup 文件,类似于检查 Docker 容器的方法:

cat /proc/1/cgroup

观察输出的内容。如果您看到与 LXC 相关的内容(如 lxc),则表示您当前正在 LXC 容器内运行。例如:

10:memory:/lxc/1234
9:devices:/lxc/1234
...

请注意,这些方法主要适用于 LXC 容器,而不一定适用于其他容器技术(如 Docker、Podman 等)。如果您使用的是其他容器技术,可能需要查找特定于该技术的文件或环境变量。

更换 PVE7 软件仓库源和 CT模板(LXC)源为国内源

PVE7 安装后默认配置的 apt 软件源和 CT(LXC)容器模板源均是官方默认的,国内使用性能不佳,建议替换为 清华 Tuna 提供的国内镜像源,速度将有一个较大的提升。

如果 pve 官网 iso 镜像下载较慢,也可在 tuna 提供的镜像站下载:https://mirrors.tuna.tsinghua.edu.cn/proxmox/iso/

注:本文以 pve 7.0.2 (debian 11 bulleye) 为例,其他版本请自行在镜像网站寻找对应地址。

替换 apt 软件源

替换前建议先更新下证书,否则可能由于证书不可用导致 https 无法使用,进而无法下载所有软件。

$ sudo apt install apt-transport-https ca-certificates

首先替换通用软件源, Debian 的软件源配置文件是 /etc/apt/sources.list,备份后将其中内容修改为以下即可。

# 默认注释了源码镜像以提高 apt update 速度,如有需要可自行取消注释
deb https://mirrors.tuna.tsinghua.edu.cn/debian/ bullseye main contrib non-free
# deb-src https://mirrors.tuna.tsinghua.edu.cn/debian/ bullseye main contrib non-free
deb https://mirrors.tuna.tsinghua.edu.cn/debian/ bullseye-updates main contrib non-free
# deb-src https://mirrors.tuna.tsinghua.edu.cn/debian/ bullseye-updates main contrib non-free

deb https://mirrors.tuna.tsinghua.edu.cn/debian/ bullseye-backports main contrib non-free
# deb-src https://mirrors.tuna.tsinghua.edu.cn/debian/ bullseye-backports main contrib non-free

deb https://mirrors.tuna.tsinghua.edu.cn/debian-security bullseye-security main contrib non-free
# deb-src https://mirrors.tuna.tsinghua.edu.cn/debian-security bullseye-security main contrib non-free

之后替换 pve 软件源,pve 镜像默认的 pve 软件源配置文件是 /etc/apt/sources.list.d/pve-enterprise.list ,备份后将其中内容替换为以下即可:

deb https://mirrors.tuna.tsinghua.edu.cn/proxmox/debian bullseye pve-no-subscription

最后更新下,速度很快:

sudo apt-get update

修改 CT Templates (LXC容器)源

将 /usr/share/perl5/PVE/APLInfo.pm 文件中默认的源地址 http://download.proxmox.com 替换为 https://mirrors.tuna.tsinghua.edu.cn/proxmox 即可。

可以使用如下命令修改:

cp /usr/share/perl5/PVE/APLInfo.pm /usr/share/perl5/PVE/APLInfo.pm_back
sed -i 's|http://download.proxmox.com|https://mirrors.tuna.tsinghua.edu.cn/proxmox|g' /usr/share/perl5/PVE/APLInfo.pm

针对 /usr/share/perl5/PVE/APLInfo.pm 文件的修改,重启后生效。

systemctl restart pvedaemon.service

之后在 pve 网页端下载 CT Templates 速度就很快了。

参考文献