The necessary changes in lxc landed in lxc/lxd https://github.com/lxc/lxc/pull/1014 and is available in version 2.0.1, currently in xenial-proposed.
It would be great if this would be backported asap. As it allows to manage the firewall within lxd instances using Puppet and probably other configuration management systems. And to use iptables-save manually
Request to backport Kernel changes from Kernel 4.5 to lts kernel 4.4 for xenial and if possible to lts kernel for 14.04
Change upstream: git.kernel. org/cgit/ linux/kernel/ git/pablo/ nf-next. git/commit/ ?id=f13f2aeed15 4da8e48f90b85e7 20f8ba39b1e881
netfilter: Set /proc/net entries owner to root in namespace
http://
This is the Kernel-side part of the fix for "iptables-save does not work inside lxd containers" /github. com/lxc/ lxd/issues/ 1978#issuecomme nt-220998013
https:/
The necessary changes in lxc landed in lxc/lxd https:/ /github. com/lxc/ lxc/pull/ 1014 and is available in version 2.0.1, currently in xenial-proposed.
It would be great if this would be backported asap. As it allows to manage the firewall within lxd instances using Puppet and probably other configuration management systems. And to use iptables-save manually