如何为LXC容器添加Capabilities?解决ptrace系统调用受限问题
Got it, let's break down exactly how to grant the necessary capabilities to allow ptrace system calls in an LXC container—this is restricted by default for good security reasons, so we need to explicitly whitelist the right permission.
1. Adding Capabilities When Creating a New Container
If you're setting up a fresh container, you can include the required capability right at creation time:
Using the
lxc-createcommand directly:lxc-create -n my-ptrace-container -t ubuntu -- --cap sys_ptraceThe
--cap sys_ptraceflag explicitly retains theCAP_SYS_PTRACEcapability for the container, instead of dropping it like the default behavior.Alternatively, if you're using a custom config template, add this line to your config file before creating the container:
lxc.cap.keep = sys_ptraceThis ensures the container holds onto the
sys_ptracecapability rather than stripping it out.
2. Modifying an Existing Container
For containers that are already up and running, follow these safe steps:
- First, stop the container to avoid config conflicts while editing:
lxc-stop -n my-existing-container - Locate the container's configuration file—this is typically stored at
/var/lib/lxc/my-existing-container/config(the path might shift a bit depending on your Linux distro). - Open the config file in your editor of choice, then update the capability settings:
- If there's no existing
lxc.cap.keepentry, add:lxc.cap.keep = sys_ptrace - If
lxc.cap.keepalready exists (e.g., for other capabilities likenet_admin), appendsys_ptraceto the list:lxc.cap.keep = net_admin sys_ptrace
- If there's no existing
- Critical Check: Scan for any
lxc.cap.dropentries in the config. Ifsys_ptraceis listed here, remove it—lxc.cap.droptakes priority overlxc.cap.keep, so leaving it will block the capability even if you added it to the keep list. - Save the config and restart the container:
lxc-start -n my-existing-container
Important Security Note
Granting CAP_SYS_PTRACE gives the container significant power—it lets processes inside trace and manipulate other processes, both within the container and (in rare misconfigured cases) outside. Only enable this capability if you fully trust the workload running in the container and understand the security tradeoffs.
内容的提问来源于stack exchange,提问作者vaishali jhalani

