OpenVZ Forum


Home » Mailing lists » Users » VPS capabilities
VPS capabilities [message #21508] Wed, 10 October 2007 09:15 Go to next message
Dietmar Maurer is currently offline  Dietmar Maurer
Messages: 52
Registered: March 2007
Member
Where can I find more information about vps capabilities, i.e. what
exactly is:

NET_BIND_SERVICE
KILL
LINUX_IMMUTABLE
NET_ADMIN
SYS_CHROOT
VE_ADMIN

Is there any ocumentation about that available?

- Dietmar
Re: VPS capabilities [message #21515 is a reply to message #21508] Wed, 10 October 2007 09:41 Go to previous messageGo to next message
dev is currently offline  dev
Messages: 1693
Registered: September 2005
Location: Moscow
Senior Member

Dietmar Maurer wrote:
> Where can I find more information about vps capabilities, i.e. what
> exactly is:
> 
> NET_BIND_SERVICE
> KILL
> LINUX_IMMUTABLE
> NET_ADMIN
> SYS_CHROOT

these are std linux capabilities, so you can look at any documentation related to it,
plus comments in kernel in include/linux/capability.h and kernel sources.

> VE_ADMIN

it is a restricted subset of CAP_SYS_ADMIN+CAP_NET_ADMIN capability for VE root.
it allows to do a lot of thing allowed for std root, like configuring firewalls,
network devices, etc. but not everything, e.g. VE root can't change mtrr registers,
can't issue raw SCSI commands, etc.

Thanks,
Kirill
AW: VPS capabilities [message #21517 is a reply to message #21515] Wed, 10 October 2007 09:48 Go to previous messageGo to next message
Dietmar Maurer is currently offline  Dietmar Maurer
Messages: 52
Registered: March 2007
Member
Ah -i see. So it is possible to run vzctl inside a vps and do most vps
admin tasks there?

- Dietmar

>> VE_ADMIN
>
>it is a restricted subset of CAP_SYS_ADMIN+CAP_NET_ADMIN capability for
VE root.
>it allows to do a lot of thing allowed for std root, like configuring
firewalls,
>network devices, etc. but not everything, e.g. VE root can't change
mtrr 
>registers, can't issue raw SCSI commands, etc.
Re: AW: VPS capabilities [message #21518 is a reply to message #21517] Wed, 10 October 2007 10:03 Go to previous messageGo to next message
dev is currently offline  dev
Messages: 1693
Registered: September 2005
Location: Moscow
Senior Member

Most likely there answer is - possible, but not easily.
vzctl requires access to some of vps files, global
configs, ve configs etc. Theoretically it can be fixed
and adopted (e.g. to have 2 global configs: one in VE0 for
admin VPS start and one in admin VPS; files from all VEs
can also be accessiable via bind mount to admin VE),
but on practice no one tried it.

Thanks,
Kirill


Dietmar Maurer wrote:
> Ah -i see. So it is possible to run vzctl inside a vps and do most vps
> admin tasks there?
> 
> - Dietmar
> 
> 
>>>VE_ADMIN
>>
>>it is a restricted subset of CAP_SYS_ADMIN+CAP_NET_ADMIN capability for
> 
> VE root.
> 
>>it allows to do a lot of thing allowed for std root, like configuring
> 
> firewalls,
> 
>>network devices, etc. but not everything, e.g. VE root can't change
> 
> mtrr 
> 
>>registers, can't issue raw SCSI commands, etc.
> 
> 
>
AW: AW: VPS capabilities [message #21519 is a reply to message #21518] Wed, 10 October 2007 10:05 Go to previous messageGo to next message
Dietmar Maurer is currently offline  Dietmar Maurer
Messages: 52
Registered: March 2007
Member
> Most likely there answer is - possible, but not easily.
> vzctl requires access to some of vps files, global configs, 
> ve configs etc. Theoretically it can be fixed and adopted 
> (e.g. to have 2 global configs: one in VE0 for admin VPS 

or also do a bind mount for /etc/vz/ ?

> start and one in admin VPS; files from all VEs can also be 
> accessiable via bind mount to admin VE), but on practice no 
> one tried it.

I guess i will try it out ;-)

- Dietmar
Re: AW: AW: VPS capabilities [message #21520 is a reply to message #21519] Wed, 10 October 2007 10:18 Go to previous message
dev is currently offline  dev
Messages: 1693
Registered: September 2005
Location: Moscow
Senior Member

Dietmar Maurer wrote:
>  
> 
> 
>>Most likely there answer is - possible, but not easily.
>>vzctl requires access to some of vps files, global configs, 
>>ve configs etc. Theoretically it can be fixed and adopted 
>>(e.g. to have 2 global configs: one in VE0 for admin VPS 
> 
> 
> or also do a bind mount for /etc/vz/ ?

yep.

>>start and one in admin VPS; files from all VEs can also be 
>>accessiable via bind mount to admin VE), but on practice no 
>>one tried it.
> 
> 
> I guess i will try it out ;-)

one bigger problem - networking setup (e.g. routes) in VE0 :/

Kirill
Previous Topic: linux-2.6.22-ovz004
Next Topic: 2.6.22.ovz00x spec file
Goto Forum:
  


Current Time: Fri Oct 24 20:34:20 GMT 2025

Total time taken to generate the page: 0.15624 seconds