Raspberry Pi3B(Ubuntu MATE 16.04)创建LXD unprivileged container出错求助
Hey there, let's work through this unprivileged LXD container problem on your Pi 3B. First, let's confirm your setup steps to make sure we're aligned:
sudo apt install lxd
sudo lxd init
Do you want to configure a new storage pool (yes/no) [default=yes]? yes
Name of the storage backend to use (dir or zfs) [default=dir]: dir
Would you like LXD to be available over the network (yes/no) [default=no]? ...
Ubuntu MATE 16.04's LXD (version ~2.0.x) has a few quirks with unprivileged containers on ARM, so let's go through fixes step by step:
1. Enable User Namespaces (Critical for Unprivileged Containers)
First, check if user namespaces are enabled on your kernel:
sysctl kernel.unprivileged_userns_clone
If it returns 0, we need to enable it permanently:
- Edit
/etc/sysctl.confand add this line:kernel.unprivileged_userns_clone=1 - Apply the change immediately:
sudo sysctl -p /etc/sysctl.conf
2. Configure UID/GID Mapping for Your User
Unprivileged containers rely on mapping container UIDs/GIDs to unused ranges on your host. LXD doesn't set this up automatically for unprivileged mode in 16.04:
- Add your user to the
lxdgroup (log out and back in afterward for this to take effect):sudo usermod -aG lxd $USER - Create the LXD config directory for your user:
mkdir -p ~/.config/lxd - Create a
default.conffile with a safe UID/GID mapping (adjust ranges if needed):
This maps container UIDs 0-65535 to host UIDs 100000-165535 (unused by default). Lock down the file permissions:uid 100000 65536 gid 100000 65536chmod 600 ~/.config/lxd/default.conf
3. Switch to a User-Owned Unprivileged LXD Instance
When you ran sudo lxd init, you set up a system-wide privileged instance. For unprivileged containers, we need a user-owned instance:
- Stop and disable the system LXD service:
sudo systemctl stop lxd sudo systemctl disable lxd - Initialize the user LXD instance:
Follow the prompts: stick withlxd init --userdirstorage (ZFS is tricky on Pi 3B), and choosenofor network access unless you specifically need it.
4. Test Creating an Unprivileged Container
Now try launching an ARM-compatible container (match your host's Ubuntu 16.04 armhf architecture):
lxc launch ubuntu:16.04 unpriv-test
Check if it runs with:
lxc list
Troubleshooting Tips
- Permission denied errors: Double-check you logged out/in after joining the
lxdgroup, and verify~/.config/lxd/default.confhas the correct permissions. - Container fails to start: Check logs with
lxc log show unpriv-testfor specific errors. Make sure your kernel is up to date:sudo apt update && sudo apt upgrade
内容的提问来源于stack exchange,提问作者CH123

