Confirmed. systemd-hostnamed.service has "PrivateNetwork=yes" (to lock down privileges), but unprivileged lxd containers cannot create new network namespaces, thus you get the 225/NETWORK .
Confirmed. systemd- hostnamed. service has "PrivateNetwork =yes" (to lock down privileges), but unprivileged lxd containers cannot create new network namespaces, thus you get the 225/NETWORK .