You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为LXC容器添加Capabilities?解决ptrace系统调用受限问题

Enabling ptrace in LXC Containers via Capabilities

Got it, let's break down exactly how to grant the necessary capabilities to allow ptrace system calls in an LXC container—this is restricted by default for good security reasons, so we need to explicitly whitelist the right permission.

1. Adding Capabilities When Creating a New Container

If you're setting up a fresh container, you can include the required capability right at creation time:

  • Using the lxc-create command directly:

    lxc-create -n my-ptrace-container -t ubuntu -- --cap sys_ptrace
    

    The --cap sys_ptrace flag explicitly retains the CAP_SYS_PTRACE capability for the container, instead of dropping it like the default behavior.

  • Alternatively, if you're using a custom config template, add this line to your config file before creating the container:

    lxc.cap.keep = sys_ptrace
    

    This ensures the container holds onto the sys_ptrace capability rather than stripping it out.

2. Modifying an Existing Container

For containers that are already up and running, follow these safe steps:

  1. First, stop the container to avoid config conflicts while editing:
    lxc-stop -n my-existing-container
    
  2. Locate the container's configuration file—this is typically stored at /var/lib/lxc/my-existing-container/config (the path might shift a bit depending on your Linux distro).
  3. Open the config file in your editor of choice, then update the capability settings:
    • If there's no existing lxc.cap.keep entry, add:
      lxc.cap.keep = sys_ptrace
      
    • If lxc.cap.keep already exists (e.g., for other capabilities like net_admin), append sys_ptrace to the list:
      lxc.cap.keep = net_admin sys_ptrace
      
  4. Critical Check: Scan for any lxc.cap.drop entries in the config. If sys_ptrace is listed here, remove it—lxc.cap.drop takes priority over lxc.cap.keep, so leaving it will block the capability even if you added it to the keep list.
  5. Save the config and restart the container:
    lxc-start -n my-existing-container
    

Important Security Note

Granting CAP_SYS_PTRACE gives the container significant power—it lets processes inside trace and manipulate other processes, both within the container and (in rare misconfigured cases) outside. Only enable this capability if you fully trust the workload running in the container and understand the security tradeoffs.

内容的提问来源于stack exchange,提问作者vaishali jhalani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:09:11