Add to your contaier config /etc/pve/lxc/XXX.conf
:
lxc.apparmor.profile: unconfined
lxc.cgroup.devices.allow: a
lxc.cap.drop:
lxc.mount.auto: proc:rw sys:rw
Last verisons of kubernetes requires also shared filesystem, so add
mount --make-rshared /
into your /etc/rc.local
inside container