1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65
|
[Exec]
Boot=off
ProcessTwo=off
Ephemeral=yes
Parameters=/sbin/init -x=1
Environment=THIS=that
User=user
WorkingDirectory=/cwd
PivotRoot=/newroot
Capability=CAP_NET
DropCapability=CAP_ADMIN
AmbientCapability=CAP_SETUID
NoNewPrivileges=yes
KillSignal=SIGTERM
Personality=shy
MachineID=edbfea3309ba41ea83e2318c58a8d498
PrivateUsers=1:2
NotifyReady=no
SystemCallFilters=write
LimitCPU=10:20
LimitFSIZE=5:10
LimitDATA=100:200
LimitSTACK=1024:2048
LimitCore=0:1024
LimitRSS=1024:4096
LimitNOFILE=5:15
LimitAS=2048:4096
LimitNPROC=32:64
LimitMEMLOCK=128:256
LimitLOCKS=100:300
LimitSIGPENDING=1:3
LimitMSGQUEUE=16:32
LimitNICE=4:5
LimitRTPRIO=0:1
LimitRTTIME=2:3
OOMScoreAdjust=50
CPUAffinity=1,2,3-4
Hostname=foo.bar
ResolvConf=copy-host
Timezone=bind
LinkJournal=try-guest
SuppressSync=yes
[Files]
ReadOnly=no
Volatile=no
Bind=/bindthis
BindReadOnly=/bindthisro
BindUser=testuser
TemporaryFileSystem=/thisismytmpfs:rw
Inaccessible=yes
Overlay=/thisisanoverlay:/thisisanoverlaytoo
OverlayReadOnly=/foo:/bar:/baz:/merged
PrivateUsersOwnership=no
[Network]
Private=off
VirtualEthernet=yes
VirtualEthernetExtra=veth1:veth2
Interface=eth1 enp0s1
MACVLAN=eno1 eno2
IPVLAN=eno3 enp2s124
Bridge=bridge123 bridge125
Zone=myzone
Port=1234 156 -1
|