You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置lxc.cap.keep后LXC容器无法启动,报权限配置冲突错误

Fixing LXC Container Startup Failure Due to Conflicting lxc.cap.keep and lxc.cap.drop Configs

Got it, let's break down why you're seeing that error and how to fix it quickly.

The Root Cause

LXC doesn't let you use both lxc.cap.keep and lxc.cap.drop in the same container config—they're mutually exclusive. Here's the logic behind it:

  • lxc.cap.drop: Removes specific kernel capabilities from the container's default set.
  • lxc.cap.keep: Starts with an empty capability set and only adds the ones you explicitly list.

Having both tells LXC two conflicting rules for managing capabilities, so it bails out instead of guessing which one to follow.

Step-by-Step Fix

  1. Audit your container config
    Open /var/lib/lxc/container_name/config and look for any lines starting with lxc.cap.drop. You have two valid options here:

    • Option 1: Stick with lxc.cap.keep
      Delete all lxc.cap.drop entries from the config. This tells LXC to only grant the sys_ptrace capability to your container (you can add more capabilities to the lxc.cap.keep line later, separated by spaces).
    • Option 2: Use lxc.cap.drop instead
      If you want the container to keep most default capabilities plus sys_ptrace, check if sys_ptrace is listed in a lxc.cap.drop line. If it is, just remove that single entry from the lxc.cap.drop list—no need for lxc.cap.keep at all.
  2. Test the fix
    Save the config file, then try starting your container again:

    lxc-start -n container_name
    

    If you run into syntax issues, validate the config with this command:

    lxc-checkconfig /var/lib/lxc/container_name/config
    

Quick Security Note

Be cautious with the sys_ptrace capability—it allows processes to trace and manipulate other processes inside the container. Only enable it if your use case absolutely requires it, as it can introduce unnecessary security risks.

内容的提问来源于stack exchange,提问作者vaishali jhalani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:08:08