Skip to content

Instantly share code, notes, and snippets.

@ey3ball
Forked from bloodearnest/setup-lxd-profile.sh
Created September 6, 2016 15:20
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save ey3ball/876abdbf1b3502dc43191a1db7e7f335 to your computer and use it in GitHub Desktop.
Save ey3ball/876abdbf1b3502dc43191a1db7e7f335 to your computer and use it in GitHub Desktop.
#!/bin/bash
set -eu
_UID=$(id -u)
GID=$(id -g)
GROUP=$(id -gn)
SUBUID=root:$_UID:1
SUBGID=root:$GID:1
# give lxd permission to map your user/group id through
grep $SUBUID /etc/subuid -qs || sudo usermod --add-subuids ${_UID}-${_UID} --add-subgids ${GID}-${GID} root
UID_OFFSET=$(grep 'root:.*:65536' /etc/subuid | head -1 | awk -F: '{ print $2 }')
GID_OFFSET=$(grep 'root:.*:65536' /etc/subgid | head -1 | awk -F: '{ print $2 }')
# set up a separate key to make sure we can log in automatically via ssh
# with $HOME mounted
KEY=$HOME/.ssh/id_lxd_$USER
PUBKEY=$KEY.pub
AUTHORIZED_KEYS=$HOME/.ssh/authorized_keys
[ -f $PUBKEY ] || ssh-keygen -f $KEY -N '' -C "key for local lxds"
grep "$(cat $PUBKEY)" $AUTHORIZED_KEYS -qs || cat $PUBKEY >> $AUTHORIZED_KEYS
# create a profile to control this, name it after $USER
lxc profile create $PROFILE &> /dev/null || true
# configure profile
# this will rewrite the whole profile
cat << EOF | lxc profile edit $USER
name: $USER
description: allow home dir mounting for $USER
config:
# this part maps the special uid/gid in the container to the correct host uid/gid
raw.lxc: |
lxc.id_map =
lxc.id_map = u 0 $UID_OFFSET $(($_UID - 1))
lxc.id_map = g 0 $GID_OFFSET $(($GID - 1))
lxc.id_map = u $_UID 1000 1
lxc.id_map = g $GID 1000 1
lxc.id_map = u $(($_UID + 1)) $(($UID_OFFSET + $_UID + 1)) $((65536 - $_UID - 1))
lxc.id_map = g $(($GID + 1)) $(($GID_OFFSET + $GID + 1)) $((65536 - $GID - 1))
user.vendor-data: |
#cloud-config
users:
- name: $USER
groups: sudo
shell: $SHELL
sudo: ['ALL=(ALL) NOPASSWD:ALL']
# ensure users shell is installed
packages:
- $(dpkg -S $(readlink -m $SHELL) | cut -d: -f1)
# The dhclient is a workaround for dns, see lp:1600766
runcmd:
- "dhclient eth0"
# this section adds your \$HOME directory into the container. This is useful for vim, bash and ssh config, and such like.
devices:
home:
type: disk
source: $HOME
path: $HOME
EOF
# to launch a container using this profile:
# lxc launch ubuntu: -p default -p $USER
# to add an additional bind mount
# lxc config device add <container> <device name> disk source=/path/on/host path=path/in/container
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment