惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
L
Lohrmann on Cybersecurity
T
Threatpost
T
Threat Research - Cisco Blogs
C
Cybersecurity and Infrastructure Security Agency CISA
S
Schneier on Security
Engineering at Meta
Engineering at Meta
Scott Helme
Scott Helme
博客园 - 三生石上(FineUI控件)
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
V
Visual Studio Blog
I
Intezer
L
LangChain Blog
Apple Machine Learning Research
Apple Machine Learning Research
S
Securelist
C
Cyber Attacks, Cyber Crime and Cyber Security
B
Blog RSS Feed
M
MIT News - Artificial intelligence
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
NISL@THU
NISL@THU
Cisco Talos Blog
Cisco Talos Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
H
Hackread – Cybersecurity News, Data Breaches, AI and More
阮一峰的网络日志
阮一峰的网络日志
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
The Cloudflare Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Vercel News
Vercel News
Stack Overflow Blog
Stack Overflow Blog
The Hacker News
The Hacker News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Register - Security
The Register - Security
Simon Willison's Weblog
Simon Willison's Weblog
Security Latest
Security Latest
C
Cisco Blogs
量子位
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Proofpoint News Feed
Cyberwarzone
Cyberwarzone
Y
Y Combinator Blog
C
CERT Recently Published Vulnerability Notes
T
Tenable Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
Project Zero
Project Zero
D
Darknet – Hacking Tools, Hacker News & Cyber Security
A
Arctic Wolf
K
Kaspersky official blog

Proxmox Support Forum

[SOLVED] - Github Auth for Mirrors-Kernel Repo? [Automation] Mass migration tool for MS Win11/Server Proxmox GUI hang - not response is it possible to reject or quarantine spam based on conditions I set ? The PVENode task list in PVE9 is partially obscured due to the terminal font being too large. About 100% error reporting due to pveproxy.service hooks Kubernetes overlay networking breaks when upgrading from PVE 9.1 to PVE 9.2.3 Zentraler Speicher No space left on device Combine datastore and direct file archival to tape Kernel panic VFS: Unable to mount root fs on unknown-block (0,0) sobald ein 7.x Kernel verwendet wird. How to migrate disk of a VM from one ZFS to another Windows Server 2025 fails to boot after PVE 9.2 / Linux 7.0 Kernel upgrade Cannot Install Proxmox on T610 Poweredge with H700 PERC card sdn Config. gateway not reachable How to safely change domain/FQDN? Welche Filterquote erreicht ihr? NFS Share status unknown on 2 of 5 nodes Can't connect to PVE9 consoles [solved] Can't connect to PVE9 consoles [solved] [SOLVED] - Use secondary network for PVE commands Created cluster, one node storage gone BUG: proxmox mail gateway FROM = null bypass spam filtering Moving existing PBS from VMWare workstation to PVE cluster Does eBGP SDN fabric support external peering? Bug: PDM 1.1 not recognizing valid license status Proxmox GUI hang - not response PVE crashes unexpectedly Proxmox Backup Server 4.2 released! Advice ceph-osd crashes with kernel 6.17.2-1-pve on Dell system [META] Links on Proxmox Forum Website Hardwarer oder Software RAID Joining a cluster with already created guests VM PDM missing backup jobs from PVE / Log retention Remove VM.Monitor from all users/roles, PVE 9.2 Proxmox Freezing (new instalation) 9.2.2 - Intel 12700T No Web gui and random connection reset by peer [SOLVED] - i40e module for X710 Intel NIC Dutch Proxmox Day 2026 How pools use the space Corosync initiiert Reboot trotz Verfügbarkeit der Systeme Opt-in Linux 7.0 Kernel for Proxmox VE 9 available After PVE 8to9 upgrade, unable to check guest fs freeze status Problem with MegaRAID SAS3508 controller proxmox-kernel-7.0.2-6-pve failing network service Auto sync guest time after rollback of VM snapshot with RAM/state Broadcom BCM57504 (100G) bnxt_en TX timeout and NIC reset on Proxmox 8.1.5 — while BCM57414 (25G) works fine on same host QEMU 11.0 available on pve-test and pve-no-subscription as of now 350 MPM Solventless Lamination Machine for High-Speed Flexible Packaging Making sense of NVMe zfs and SMART errors [SOLVED] - PVE loses network connection after kernel upgrade to proxmox-kernel-7.0.0-3-pve [SOLVED] - Remove or reset cluster configuration. Proxmox 8.4.1 Fresh Install BCM57416 10G Ethernet Adapter Not Recognized PDM 1.1.1 unable to add AD realm with anonymous search [TUTORIAL] - Developer Workstation (Proxmox-VE 9) with cinnamon (LMDE7) SDN zone shows "pending" on peer nodes after node reboot (9.2.x) Cluster not quorate - extending auth key lifetime! Proxmox not rebooting properly (SOLVED) Proxmox 9 Stuck on loading initial ramdisk With new HA-Disarm Feature is there a Documentation for NUT Setup on Clusters? Proxmox 8.3 Installation Issue on ProLiant DL380 Gen9 Cluster networking setup LXC System images unavailable [SOLVED] - Fix: NVIDIA Drivers Failing after upgrade to Proxmox 9.2.2 (Kernel 7.0.2-6-pve) / NovaCore Conflict Install NUT directly on Proxmox VE and control guests from here driver usb for windows 7 System startup error and no network: Failed to start ifupdown2-pre.service - Helper to synchronize boot up for ifupdown. PBS backup space grow up constantly Proxmox Datacenter Manager 1.1 released! IPv4 not available in newly created VM Recommended Setup for Offsite Proxmox Backups? Hetzner Storage Box & Remote PBS Challenges duplicate, please delete this passthrought an USB device "by ID" to CT PDM Installer Freezes at 66% Tried PDM for the first time (version 1.1) - had issues PDM 1.1 automated install Suche Server-Provider für Proxmox connecting sdn to edge firewall SDN, IPAM & DHCP Migrating from read-only file system Ubuntu 26.04 installation fails for unknown reason Status Unbekannt nach Cluster Join Installing Proxmox Backup Server on Mac Mini (Late 2012) kernel 7.0 performance issue with zfs pools PVE becomes unreachable via ethernet but OS is running [SOLVED] - New 9.2 install - can't find 7.0.2-6-pve , not all the time [SOLVED] - Backup and dedupe a VM with LUKS Gibt es mit PVE 2.x ggf. Änderungen bei der RAM-Nutzung, bzw. deren Anzeige bei VMs? I need help for setting up backup solution Way more NAGware, very little functionality, bugs galore Root squashing virtiofsd with --uid-map Intel ixgbe Driver Update Fail Passkey Login (not 2FA) Roblox VM detection - can be overcome? [TUTORIAL] - ZFS-Autosnaptshot inkl. Rollback und Daten direkt recovern (Windows/Linux) How to stop PVE Kernel upgrade [SOLVED] - very long waiting to log in to lxc debian 11 ssh [TUTORIAL] - Configuring Fusion-Io (SanDisk) ioDrive, ioDrive2, ioScale and ioScale2 cards with Proxmox Increase maximum USB devices in vm.conf
Using ZFS commands inside LXC container
invalid@exam · 2026-06-28 · via Proxmox Support Forum

Hi,

I am trying to set up a debian 13 LXC container on Proxmox 9.0.11 from which I can manage ZFS pools. I managed to bind the ZFS storage to the container, however, now I am struggling to get ZFS commands to work inside the container. When I try to use a ZFS command, I get

Code:

zpool status
Failed to initialize the libzfs library.

What I have done so far is that I added the proxmox repos inside the container, so the ZFS packages inside the container are the same version as on the proxmox host, as the packages from the debian repos were a few versions behind. Furthermore, I added this to the LXC config file:

Code:

lxc.cgroup.devices.allow: c 10:249 rwm
lxc.mount.entry: /dev/zfs dev/zfs none bind,create=file 0 0
lxc.mount.entry: /dev/fuse dev/fuse none bind,create=file 0 0
lxc.mount.entry: /sys/class sys/class none bind,rw,create=dir 0 0
lxc.mount.entry: /sys/devices sys/devices none bind,rw,create=dir 0 0
lxc.apparmor.profile: unconfined
lxc.cap.drop:
lxc.mount.auto: proc:mixed sys:mixed

From my understanding, binding /lib/modules to the container should solve the issue, but using

Code:

lxc.mount.entry: /lib/modules /lib/modules none rbind,ro,create=dir 0 0

is not doing anything and the container starts up with no error message.
Those are the ZFS related packages that I have installed inside the container:

Code:

libzfs6linux/stable,now 2.3.4-pve1 amd64 [installed]
zfs-dkms/stable,now 2.3.2-2 all [installed]
zfs-initramfs/stable,now 2.3.4-pve1 all [installed]
zfs-zed/stable,now 2.3.4-pve1 amd64 [installed]
zfsutils-linux/stable,now 2.3.4-pve1 amd64 [installed]

Maybe I am overlooking something obvious or someone has an idea where to start troubleshooting this.

Thanks for your help!

Were you ever able to figure this out? I have a similar use case.

In my case it is relatively simple - I bind mount a external USB hard drive that is formatted as ZFS to a LXC running Debian 13, and would like to execute ZFS commands from within the LXC on the bind mounted device.

No, you will isolation in VM and LXC from the Hardwarelevel.
And ZFS Commands need root access!

Last edited:

Is that the case for both privileged LXCs as well as unprivileged LXCs?

Did you install zfsutils-linux in the Debian LXC? Leaving aside the issues of a non privileged container, a Debian LXC won't have the user space tools installed until you install the zfsutils-linux package through apt in your LXC.

No, you will isolation in VM and LXC from the Hardwarelevel.
And ZFS Commands need root access!

I just wanted to let you know that you do not need root access with delegation, except for mounting and unmounting (It's a linux restriction not zfs)

I'm looking to setup something like this as well. I have a few linux boxes that I want to shift to lxc and being able to do admin stuff from inside would be very useful.

I'm looking to setup something like this as well. I have a few linux boxes that I want to shift to lxc and being able to do admin stuff from inside would be very useful.

I'm curious- what would be the use case for this? in my view containers exist to isolate an application from the underlying hardware. if a container has access it loses its purpose to exist.

I'm curious- what would be the use case for this? in my view containers exist to isolate an application from the underlying hardware. if a container has access it loses its purpose to exist.

Your view is flawed. You're not giving the container access to the underlying hardware, you are giving the container the ability to manage it's own files. The container can make datasets, snapshots, do it's own backups if needed, change it's recordsize, etc. For a single application it may not be as important, but if you are using the containers as a lightweight vm it's far more attractive. I'm going to combine a bunch of machines into 1 server, most are fairly specialized: home automation, plex/jellyfin, general light terminal use, etc and containers are much easier to share resources.

Sure, i could setup sanoid on proxmox directly, but then I have to keep up with dataset names, and if they get moved to another host the snapshotting and backups dont, the uid/gid get all screwed up if they are unpriv. containers, etc.

I Imagine you're very popular with you peers.

. I'm going to combine a bunch of machines into 1 server, most are fairly specialized: home automation, plex/jellyfin, general light terminal use, etc and containers are much easier to share resources.

Why bother with a hypervisor then? just set up docker and linux and you're done...

I Imagine you're very popular with you peers.

I'm sorry I didn't sugarcoat it. If you are looking at something incorrectly what do you call it?

Why bother with a hypervisor then? just set up docker and linux and you're done...

Well. That's what I have. I want to combine multiple machines onto one as well as with VMs. Not everything runs in docker, either. I am bothering setting up a hypervisor to supervise things together on one box. What do you use hypervisors for? Something different? If you aren't familiar with the features and power of zfs I'm not surprised why you wouldn't get the desire for delegation. It's really powerful.

If you are looking at something incorrectly what do you call it?

Ignorance. although I usually leave room for the possibility the ignorance is mine. there is no more certainty in being wrong then not allowing for a different perspective. believing you're right and being, err, forceful about it says more about you then you perhaps intend.

zfs I'm not surprised why you wouldn't get the desire for delegation. It's really powerful.

ZFS is powerful. its also a tool. you dont need pve to use it.

What do you use hypervisors for? Something different?

different then you? most certainly. it's to create hardware separated namespaces. zfs can function as a mechanism to allow that, but in all honesty I dont use zfs as its failure domain is too narrow for high availability. If hardware seperation isnt necessary or desirable a hypervisor is unnecessary complexity.

Ignorance. although I usually leave room for the possibility the ignorance is mine. there is no more certainty in being wrong then not allowing for a different perspective. believing you're right and being, err, forceful about it says more about you then you perhaps intend.

ZFS is powerful. its also a tool. you dont need pve to use it.

different then you? most certainly. it's to create hardware separated namespaces. zfs can function as a mechanism to allow that, but in all honesty I dont use zfs as its failure domain is too narrow for high availability. If hardware seperation isnt necessary or desirable a hypervisor is unnecessary complexity.

So I want (more) hardware separation than is currently offered, but is possible with existing tools. I care about data integrity, transparent compression, and instant snapshots that can be send to other machines more than HA. And you still missed the meaning of my comment, delegated datasets un-abstract a container from the hardware as much as making a new directory does. It doesn't at all. In fact, currently, there is a *larger* lack of separation between the containers and hardware than it would be with delegation. As I've already said, currently many maintenance tasks and settings can only be done on the host and they wouldn't move with the container.

So I want (more) hardware separation than is currently offered, but is possible with existing tools.

Bingo. why arent you using those?

Bingo. why arent you using those?

Because they are tucked away in proxmox and I'm asking for them to be exposed to be more easily usable. You seem to be stuck on your way is the only correct way.

I managed to get ZFS working in a priviledged Alpine LXC container. You need to create the container and pass through /proc and /dev/zfs to the container. To do that, create the container and do a device passthrough for /dev/zfs and execute pct set <LXC ID> -mp0 /proc,mp=/proc to mount procfs in the container.

Then you can install the ZFS utils in the LXC (apk add zfs) and manage your datasets in the container.

Why is this useful? I want to do automatic snapshots with tools like sanoid, but do not want to clutter my Proxmox host with too many packages.