[Lxc-users] multiple containers with a sheared rootfs

amin dce3000 at gmail.com
Wed Sep 22 07:12:35 UTC 2010


hi dear
i want to isolate my services each on a separate container to provide more
isolation, although i am running in a restricted size hard drive i can't
provide more than one rootfs with debootstrap

i try to install my system containers with a shared rootfs distinct proc and
var, means i want every thing shared but /var /proc
to do so i try following configuration as my lxc.mount :




none /media/ssh/proc proc defaults 0 0
/media/ssh/var  /media/ssh/var none  rw,bind 0 0
/media/jail/bin /media/ssh/bin none  rw,bind 0 0
/media/jail/boot  /media/ssh/boot none  rw,bind 0 0
/media/jail/dev  /media/ssh/dev none  rw,bind 0 0
/media/jail/etc  /media/ssh/etc none  rw,bind 0 0
/media/jail/home  /media/ssh/home none  rw,bind 0 0
/media/jail/lib /media/ssh/lib none  rw,bind 0 0
/media/jail/media /media/ssh/media none  rw,bind 0 0
/media/jail/mnt /media/ssh/mnt none  rw,bind 0 0
/media/jail/opt /media/ssh/opt none  rw,bind 0 0
/media/jail/root /media/ssh/root none  rw,bind 0 0
/media/jail/sbin /media/ssh/sbin none  rw,bind 0 0
/media/jail/selinux /media/ssh/selinux none  rw,bind 0 0
/media/jail/srv /media/ssh/srv  none  rw,bind 0 0
/media/jail/sys /media/ssh/sys none  rw,bind 0 0
/media/jail/tmp  /media/ssh/tmp none  rw,bind 0 0
/media/jail/usr  /media/ssh/usr none  rw,bind 0 0


but i get error indicating:
lxc-start: No such file or directory - failed to mount '/media/jail/bin' on
'/media/ssh/bin'
lxc-start: failed to setup the mounts for 'ssh'
lxc-start: failed to setup the container
couldn't start lxc(0)
could not create lxc (0)

any idea to refine my work ?
am i supposed to use application container instead? and does it provide
enough isolation ?
thanks

-- 
with the best regards toward you
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linuxcontainers.org/pipermail/lxc-users/attachments/20100922/b4c66f47/attachment.html>


More information about the lxc-users mailing list