You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Raspberry Pi3B(Ubuntu MATE 16.04)创建LXD unprivileged container出错求助

Fixing Unprivileged LXD Container Issues on Raspberry Pi 3B (Ubuntu MATE 16.04)

Hey there, let's work through this unprivileged LXD container problem on your Pi 3B. First, let's confirm your setup steps to make sure we're aligned:

sudo apt install lxd
sudo lxd init
Do you want to configure a new storage pool (yes/no) [default=yes]? yes
Name of the storage backend to use (dir or zfs) [default=dir]: dir
Would you like LXD to be available over the network (yes/no) [default=no]? ...

Ubuntu MATE 16.04's LXD (version ~2.0.x) has a few quirks with unprivileged containers on ARM, so let's go through fixes step by step:

1. Enable User Namespaces (Critical for Unprivileged Containers)

First, check if user namespaces are enabled on your kernel:

sysctl kernel.unprivileged_userns_clone

If it returns 0, we need to enable it permanently:

  • Edit /etc/sysctl.conf and add this line:
    kernel.unprivileged_userns_clone=1
    
  • Apply the change immediately:
    sudo sysctl -p /etc/sysctl.conf
    

2. Configure UID/GID Mapping for Your User

Unprivileged containers rely on mapping container UIDs/GIDs to unused ranges on your host. LXD doesn't set this up automatically for unprivileged mode in 16.04:

  • Add your user to the lxd group (log out and back in afterward for this to take effect):
    sudo usermod -aG lxd $USER
    
  • Create the LXD config directory for your user:
    mkdir -p ~/.config/lxd
    
  • Create a default.conf file with a safe UID/GID mapping (adjust ranges if needed):
    uid 100000 65536
    gid 100000 65536
    
    This maps container UIDs 0-65535 to host UIDs 100000-165535 (unused by default). Lock down the file permissions:
    chmod 600 ~/.config/lxd/default.conf
    

3. Switch to a User-Owned Unprivileged LXD Instance

When you ran sudo lxd init, you set up a system-wide privileged instance. For unprivileged containers, we need a user-owned instance:

  • Stop and disable the system LXD service:
    sudo systemctl stop lxd
    sudo systemctl disable lxd
    
  • Initialize the user LXD instance:
    lxd init --user
    
    Follow the prompts: stick with dir storage (ZFS is tricky on Pi 3B), and choose no for network access unless you specifically need it.

4. Test Creating an Unprivileged Container

Now try launching an ARM-compatible container (match your host's Ubuntu 16.04 armhf architecture):

lxc launch ubuntu:16.04 unpriv-test

Check if it runs with:

lxc list

Troubleshooting Tips

  • Permission denied errors: Double-check you logged out/in after joining the lxd group, and verify ~/.config/lxd/default.conf has the correct permissions.
  • Container fails to start: Check logs with lxc log show unpriv-test for specific errors. Make sure your kernel is up to date:
    sudo apt update && sudo apt upgrade
    

内容的提问来源于stack exchange,提问作者CH123

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:59:10