X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=elogind.git;a=blobdiff_plain;f=man%2Fsystemd-nspawn.xml;h=feafb31bc026f1da9f3ea3e3c3b80116365de039;hp=8adcd946b0438e6da634576eefc780a99ada068a;hb=a0f9c810faa022c264bf534ab9495e0e9f617962;hpb=870c4365cf3d407270788abe14d216a636ecf6c3 diff --git a/man/systemd-nspawn.xml b/man/systemd-nspawn.xml index 8adcd946b..feafb31bc 100644 --- a/man/systemd-nspawn.xml +++ b/man/systemd-nspawn.xml @@ -133,6 +133,28 @@ Container Interface specification. + + As a safety check + systemd-nspawn will verify the + existence of /etc/os-release in + the container tree before starting the container (see + os-release5). It + might be necessary to add this file to the container + tree manually if the OS of the container is too old to + contain this file out-of-the-box. + + + + Incompatibility with Auditing + + Note that the kernel auditing subsystem is + currently broken when used together with + containers. We hence recommend turning it off entirely + by booting with audit=0 on the + kernel command line, or by turning it off at kernel + build time. If auditing is enabled in the kernel + operating systems booted in an nspawn container might + refuse log-in attempts. @@ -202,10 +224,25 @@ + + + + + Sets the machine name + for this container. This name may be + used to identify this container on the + host, and is used to initialize the + container's hostname (which the + container can choose to override, + however). If not specified the last + component of the root directory of the + container is used. + + - Set the specified uuid + Set the specified UUID for the container. The init system will initialize /etc/machine-id @@ -237,7 +274,7 @@ Mount the root file - system read only for the + system read-only for the container. @@ -246,7 +283,7 @@ List one or more additional capabilities to grant the - container. Takes a comma separated + container. Takes a comma-separated list of capability names, see capabilities7 for more information. Note that the @@ -345,7 +382,7 @@ # systemd-nspawn -bD /srv/mycontainer This installs a minimal Fedora distribution into - the directory /srv/mycontainer/ and + the directory /srv/mycontainer/ and then boots an OS in a namespace container in it. @@ -382,7 +419,7 @@ (as viewed from the outside) of the launched process, and it can be used to enter the container. - # nsenter -muinpt $PID + # nsenter -m -u -i -n -p -t $PID nsenter1 is part of