Automatic Separation of /tmp for LXD Containers
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Canonical Juju |
Triaged
|
Wishlist
|
Unassigned |
Bug Description
Currently, Juju does not support an automated process for separating the /tmp directory for LXD containers onto a separate disk partition. Administrators must manually intervene using LXD-specific procedures, which is not feasible or scalable for large deployments.
This is how we do it with lxd:
```
lxc storage volume create default c1-tmp size=1GiB
lxc config device add c1 tmp disk source=c1-tmp pool=default
lxc start c1
lxc exec c1 -- findmnt --mountpoint /tmp
TARGET SOURCE FSTYPE OPTIONS
/tmp /dev/mapper/
```
The lack of this feature complicates compliance with CIS standards, potentially exposing deployments to security risks associated with shared /tmp directories.
Changed in juju: | |
status: | New → Triaged |
importance: | Undecided → Wishlist |
subscribed field-high