Hi there, @tomp! Yeah, ofc
# container config
# Common and Puppet specified includes
lxc.include = /usr/share/lxc/config/centos.common.conf
lxc.include = /var/lib/lxc/test-1/conf.d
# Distribution configuration
lxc.arch = x86_64
# Container specific configuration
lxc.rootfs.path = loop:/var/lib/lxc/test-1/rootdev
lxc.uts.name = test-1.local
# Local additions
lxc.monitor.unshare = 1
lxc.environment = TERM=linux
lxc.tty.max = 2
lxc.autodev = 1
lxc.start.auto = 1
lxc.prlimit.nofile = 10000
# Apparmor section
lxc.apparmor.profile = generated
lxc.apparmor.allow_nesting = 0
lxc.apparmor.raw = deny mount -> /proc/,
lxc.apparmor.raw = deny mount -> /sys/,
# Cgroups common
lxc.cgroup.dir.monitor = lxc.monitor/test-1
lxc.cgroup.dir.container = lxc/test-1
lxc.cgroup.dir.container.inner = ns
# Hooks & bindings
lxc.hook.mount = /var/lib/lxc/test-1/setup_routes
lxc.hook.pre-start = /usr/local/sbin/lxc/hook_pre_start_mkdir /srv/test
lxc.mount.entry = tmpfs srv/ramdisk/test tmpfs nodev,nosuid,size=1G,create=dir 0 0
lxc.mount.entry = /srv/test usr/share/test none ro,bind,create=dir 0 0
# From conf.d
lxc.cgroup.memory.limit_in_bytes = 5G
lxc.cgroup.memory.memsw.limit_in_bytes = 5G
lxc.net.0.flags = up
lxc.net.0.ipv4.address = 192.168.16.10/24
lxc.net.0.link = br0
lxc.net.0.name = eth0
lxc.net.0.type = veth
lxc.net.1.flags = up
lxc.net.1.ipv4.address = 10.0.0.2/24
lxc.net.1.ipv4.gateway = 10.0.0.253
lxc.net.1.link = br155
lxc.net.1.name = eth1
lxc.net.1.type = veth
#
# before stop
#
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,SLAVE,UP,LOWER_UP> mtu 1500 qdisc mq master bond0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
3: eth1: <BROADCAST,MULTICAST,SLAVE,UP,LOWER_UP> mtu 1500 qdisc mq master bond0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
4: eth2: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 44:a8:42:27:51:43 brd ff:ff:ff:ff:ff:ff
5: eth3: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 44:a8:42:27:51:44 brd ff:ff:ff:ff:ff:ff
262: veth5b63a00@if261: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br0 state UP group default
link/ether be:5e:9a:11:c7:ce brd ff:ff:ff:ff:ff:ff link-netnsid 2
inet6 fe80::bc5e:9aff:fe11:c7ce/64 scope link
valid_lft forever preferred_lft forever
6: bond0: <BROADCAST,MULTICAST,MASTER,UP,LOWER_UP> mtu 1500 qdisc noqueue master br0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
7: bond0.155@bond0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br155 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
264: vethec52cbd@if263: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 36:85:65:dd:3b:42 brd ff:ff:ff:ff:ff:ff link-netnsid 2
inet6 fe80::3485:65ff:fedd:3b42/64 scope link
valid_lft forever preferred_lft forever
8: bond0.252@bond0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 192.168.252.1/30 brd 192.168.252.3 scope global bond0.252
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
9: br0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 192.168.16.50/24 brd 192.168.16.255 scope global br0
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
10: br155: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 10.0.0.1/24 brd 10.0.0.255 scope global br155
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
11: br-6697dc50ea30: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default
link/ether 02:42:30:57:f1:03 brd ff:ff:ff:ff:ff:ff
inet 192.168.100.1/24 brd 192.168.100.255 scope global br-6697dc50ea30
valid_lft forever preferred_lft forever
inet6 fe80::42:30ff:fe57:f103/64 scope link
valid_lft forever preferred_lft forever
12: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
link/ether 02:42:b8:ae:0b:18 brd ff:ff:ff:ff:ff:ff
inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
valid_lft forever preferred_lft forever
14: vethd022fc9@if13: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 56:1e:24:7f:d5:d2 brd ff:ff:ff:ff:ff:ff link-netnsid 1
inet6 fe80::541e:24ff:fe7f:d5d2/64 scope link
valid_lft forever preferred_lft forever
16: veth70f80e5@if15: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether fe:40:7f:dc:08:3f brd ff:ff:ff:ff:ff:ff link-netnsid 0
inet6 fe80::fc40:7fff:fedc:83f/64 scope link
valid_lft forever preferred_lft forever
286: vethf2517fd@if285: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 8e:e4:a4:03:84:7f brd ff:ff:ff:ff:ff:ff link-netnsid 4
inet6 fe80::8ce4:a4ff:fe03:847f/64 scope link
valid_lft forever preferred_lft forever
288: veth6f923a3@if287: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 5e:b5:7f:fc:95:6c brd ff:ff:ff:ff:ff:ff link-netnsid 5
inet6 fe80::5cb5:7fff:fefc:956c/64 scope link
valid_lft forever preferred_lft forever
290: veth258b6c6@if289: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether d2:5a:a9:ca:75:77 brd ff:ff:ff:ff:ff:ff link-netnsid 6
inet6 fe80::d05a:a9ff:feca:7577/64 scope link
valid_lft forever preferred_lft forever
292: vethfd9b486@if291: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 86:66:f4:7f:a9:ee brd ff:ff:ff:ff:ff:ff link-netnsid 7
inet6 fe80::8466:f4ff:fe7f:a9ee/64 scope link
valid_lft forever preferred_lft forever
294: veth5d88bb8@if293: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 8a:bf:ad:79:ed:30 brd ff:ff:ff:ff:ff:ff link-netnsid 8
inet6 fe80::88bf:adff:fe79:ed30/64 scope link
valid_lft forever preferred_lft forever
296: veth250919a@if295: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 02:24:46:ee:96:de brd ff:ff:ff:ff:ff:ff link-netnsid 9
inet6 fe80::24:46ff:feee:96de/64 scope link
valid_lft forever preferred_lft forever
298: vethc600360@if297: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 0a:ea:0f:fc:cb:a1 brd ff:ff:ff:ff:ff:ff link-netnsid 10
inet6 fe80::8ea:fff:fefc:cba1/64 scope link
valid_lft forever preferred_lft forever
300: veth0e54aa2@if299: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 5e:59:0e:14:bd:ec brd ff:ff:ff:ff:ff:ff link-netnsid 11
inet6 fe80::5c59:eff:fe14:bdec/64 scope link
valid_lft forever preferred_lft forever
302: veth4c3be0e@if301: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether a6:ed:c7:aa:e4:eb brd ff:ff:ff:ff:ff:ff link-netnsid 12
inet6 fe80::a4ed:c7ff:feaa:e4eb/64 scope link
valid_lft forever preferred_lft forever
304: vethe39180c@if303: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether a2:af:61:59:ce:a8 brd ff:ff:ff:ff:ff:ff link-netnsid 13
inet6 fe80::a0af:61ff:fe59:cea8/64 scope link
valid_lft forever preferred_lft forever
326: veth5WQ7E1@if325: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br0 state UP group default qlen 1000
link/ether fe:ed:4d:39:76:4e brd ff:ff:ff:ff:ff:ff link-netnsid 14
inet6 fe80::fced:4dff:fe39:764e/64 scope link
valid_lft forever preferred_lft forever
328: veth9DCBCY@if327: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br155 state UP group default qlen 1000
link/ether fe:e9:6c:ee:a1:4f brd ff:ff:ff:ff:ff:ff link-netnsid 14
inet6 fe80::fce9:6cff:feee:a14f/64 scope link
valid_lft forever preferred_lft forever
#
# inside container
#
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
325: eth0@if326: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1500 qdisc noqueue state UP qlen 1000
link/ether 36:99:3c:8f:be:16 brd ff:ff:ff:ff:ff:ff
inet 192.168.16.10/24 brd 192.168.16.255 scope global eth0
valid_lft forever preferred_lft forever
inet6 fe80::3499:3cff:fe8f:be16/64 scope link
valid_lft forever preferred_lft forever
327: eth1@if328: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1500 qdisc noqueue state UP qlen 1000
link/ether 06:3a:1e:65:7b:14 brd ff:ff:ff:ff:ff:ff
inet 10.0.0.2/24 brd 10.0.0.255 scope global eth1
valid_lft forever preferred_lft forever
inet6 fe80::43a:1eff:fe65:7b14/64 scope link
valid_lft forever preferred_lft forever
#
# after stop but net is still alive
#
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,SLAVE,UP,LOWER_UP> mtu 1500 qdisc mq master bond0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
3: eth1: <BROADCAST,MULTICAST,SLAVE,UP,LOWER_UP> mtu 1500 qdisc mq master bond0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
4: eth2: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 44:a8:42:27:51:43 brd ff:ff:ff:ff:ff:ff
5: eth3: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 44:a8:42:27:51:44 brd ff:ff:ff:ff:ff:ff
262: veth5b63a00@if261: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br0 state UP group default
link/ether be:5e:9a:11:c7:ce brd ff:ff:ff:ff:ff:ff link-netnsid 2
inet6 fe80::bc5e:9aff:fe11:c7ce/64 scope link
valid_lft forever preferred_lft forever
6: bond0: <BROADCAST,MULTICAST,MASTER,UP,LOWER_UP> mtu 1500 qdisc noqueue master br0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
7: bond0.155@bond0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br155 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
264: vethec52cbd@if263: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 36:85:65:dd:3b:42 brd ff:ff:ff:ff:ff:ff link-netnsid 2
inet6 fe80::3485:65ff:fedd:3b42/64 scope link
valid_lft forever preferred_lft forever
8: bond0.252@bond0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 192.168.252.1/30 brd 192.168.252.3 scope global bond0.252
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
9: br0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 192.168.16.50/24 brd 192.168.16.255 scope global br0
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
10: br155: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 10.0.0.1/24 brd 10.0.0.255 scope global br155
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
11: br-6697dc50ea30: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default
link/ether 02:42:30:57:f1:03 brd ff:ff:ff:ff:ff:ff
inet 192.168.100.1/24 brd 192.168.100.255 scope global br-6697dc50ea30
valid_lft forever preferred_lft forever
inet6 fe80::42:30ff:fe57:f103/64 scope link
valid_lft forever preferred_lft forever
12: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
link/ether 02:42:b8:ae:0b:18 brd ff:ff:ff:ff:ff:ff
inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
valid_lft forever preferred_lft forever
14: vethd022fc9@if13: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 56:1e:24:7f:d5:d2 brd ff:ff:ff:ff:ff:ff link-netnsid 1
inet6 fe80::541e:24ff:fe7f:d5d2/64 scope link
valid_lft forever preferred_lft forever
16: veth70f80e5@if15: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether fe:40:7f:dc:08:3f brd ff:ff:ff:ff:ff:ff link-netnsid 0
inet6 fe80::fc40:7fff:fedc:83f/64 scope link
valid_lft forever preferred_lft forever
286: vethf2517fd@if285: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 8e:e4:a4:03:84:7f brd ff:ff:ff:ff:ff:ff link-netnsid 4
inet6 fe80::8ce4:a4ff:fe03:847f/64 scope link
valid_lft forever preferred_lft forever
288: veth6f923a3@if287: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 5e:b5:7f:fc:95:6c brd ff:ff:ff:ff:ff:ff link-netnsid 5
inet6 fe80::5cb5:7fff:fefc:956c/64 scope link
valid_lft forever preferred_lft forever
290: veth258b6c6@if289: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether d2:5a:a9:ca:75:77 brd ff:ff:ff:ff:ff:ff link-netnsid 6
inet6 fe80::d05a:a9ff:feca:7577/64 scope link
valid_lft forever preferred_lft forever
292: vethfd9b486@if291: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 86:66:f4:7f:a9:ee brd ff:ff:ff:ff:ff:ff link-netnsid 7
inet6 fe80::8466:f4ff:fe7f:a9ee/64 scope link
valid_lft forever preferred_lft forever
294: veth5d88bb8@if293: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 8a:bf:ad:79:ed:30 brd ff:ff:ff:ff:ff:ff link-netnsid 8
inet6 fe80::88bf:adff:fe79:ed30/64 scope link
valid_lft forever preferred_lft forever
296: veth250919a@if295: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 02:24:46:ee:96:de brd ff:ff:ff:ff:ff:ff link-netnsid 9
inet6 fe80::24:46ff:feee:96de/64 scope link
valid_lft forever preferred_lft forever
298: vethc600360@if297: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 0a:ea:0f:fc:cb:a1 brd ff:ff:ff:ff:ff:ff link-netnsid 10
inet6 fe80::8ea:fff:fefc:cba1/64 scope link
valid_lft forever preferred_lft forever
300: veth0e54aa2@if299: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 5e:59:0e:14:bd:ec brd ff:ff:ff:ff:ff:ff link-netnsid 11
inet6 fe80::5c59:eff:fe14:bdec/64 scope link
valid_lft forever preferred_lft forever
302: veth4c3be0e@if301: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether a6:ed:c7:aa:e4:eb brd ff:ff:ff:ff:ff:ff link-netnsid 12
inet6 fe80::a4ed:c7ff:feaa:e4eb/64 scope link
valid_lft forever preferred_lft forever
304: vethe39180c@if303: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether a2:af:61:59:ce:a8 brd ff:ff:ff:ff:ff:ff link-netnsid 13
inet6 fe80::a0af:61ff:fe59:cea8/64 scope link
valid_lft forever preferred_lft forever
326: veth5WQ7E1@if325: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue master br0 state LOWERLAYERDOWN group default qlen 1000
link/ether fe:ed:4d:39:76:4e brd ff:ff:ff:ff:ff:ff link-netnsid 14
inet6 fe80::fced:4dff:fe39:764e/64 scope link
valid_lft forever preferred_lft forever
328: veth9DCBCY@if327: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br155 state UP group default qlen 1000
link/ether fe:e9:6c:ee:a1:4f brd ff:ff:ff:ff:ff:ff link-netnsid 14
inet6 fe80::fce9:6cff:feee:a14f/64 scope link
valid_lft forever preferred_lft forever
#
# after ping ends
#
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,SLAVE,UP,LOWER_UP> mtu 1500 qdisc mq master bond0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
3: eth1: <BROADCAST,MULTICAST,SLAVE,UP,LOWER_UP> mtu 1500 qdisc mq master bond0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
4: eth2: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 44:a8:42:27:51:43 brd ff:ff:ff:ff:ff:ff
5: eth3: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 44:a8:42:27:51:44 brd ff:ff:ff:ff:ff:ff
262: veth5b63a00@if261: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br0 state UP group default
link/ether be:5e:9a:11:c7:ce brd ff:ff:ff:ff:ff:ff link-netnsid 2
inet6 fe80::bc5e:9aff:fe11:c7ce/64 scope link
valid_lft forever preferred_lft forever
6: bond0: <BROADCAST,MULTICAST,MASTER,UP,LOWER_UP> mtu 1500 qdisc noqueue master br0 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
7: bond0.155@bond0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br155 state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
264: vethec52cbd@if263: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 36:85:65:dd:3b:42 brd ff:ff:ff:ff:ff:ff link-netnsid 2
inet6 fe80::3485:65ff:fedd:3b42/64 scope link
valid_lft forever preferred_lft forever
8: bond0.252@bond0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 192.168.252.1/30 brd 192.168.252.3 scope global bond0.252
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
9: br0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 192.168.16.50/24 brd 192.168.16.255 scope global br0
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
10: br155: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 44:a8:42:27:51:41 brd ff:ff:ff:ff:ff:ff
inet 10.0.0.1/24 brd 10.0.0.255 scope global br155
valid_lft forever preferred_lft forever
inet6 fe80::46a8:42ff:fe27:5141/64 scope link
valid_lft forever preferred_lft forever
11: br-6697dc50ea30: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default
link/ether 02:42:30:57:f1:03 brd ff:ff:ff:ff:ff:ff
inet 192.168.100.1/24 brd 192.168.100.255 scope global br-6697dc50ea30
valid_lft forever preferred_lft forever
inet6 fe80::42:30ff:fe57:f103/64 scope link
valid_lft forever preferred_lft forever
12: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
link/ether 02:42:b8:ae:0b:18 brd ff:ff:ff:ff:ff:ff
inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
valid_lft forever preferred_lft forever
14: vethd022fc9@if13: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 56:1e:24:7f:d5:d2 brd ff:ff:ff:ff:ff:ff link-netnsid 1
inet6 fe80::541e:24ff:fe7f:d5d2/64 scope link
valid_lft forever preferred_lft forever
16: veth70f80e5@if15: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether fe:40:7f:dc:08:3f brd ff:ff:ff:ff:ff:ff link-netnsid 0
inet6 fe80::fc40:7fff:fedc:83f/64 scope link
valid_lft forever preferred_lft forever
286: vethf2517fd@if285: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 8e:e4:a4:03:84:7f brd ff:ff:ff:ff:ff:ff link-netnsid 4
inet6 fe80::8ce4:a4ff:fe03:847f/64 scope link
valid_lft forever preferred_lft forever
288: veth6f923a3@if287: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 5e:b5:7f:fc:95:6c brd ff:ff:ff:ff:ff:ff link-netnsid 5
inet6 fe80::5cb5:7fff:fefc:956c/64 scope link
valid_lft forever preferred_lft forever
290: veth258b6c6@if289: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether d2:5a:a9:ca:75:77 brd ff:ff:ff:ff:ff:ff link-netnsid 6
inet6 fe80::d05a:a9ff:feca:7577/64 scope link
valid_lft forever preferred_lft forever
292: vethfd9b486@if291: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 86:66:f4:7f:a9:ee brd ff:ff:ff:ff:ff:ff link-netnsid 7
inet6 fe80::8466:f4ff:fe7f:a9ee/64 scope link
valid_lft forever preferred_lft forever
294: veth5d88bb8@if293: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 8a:bf:ad:79:ed:30 brd ff:ff:ff:ff:ff:ff link-netnsid 8
inet6 fe80::88bf:adff:fe79:ed30/64 scope link
valid_lft forever preferred_lft forever
296: veth250919a@if295: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 02:24:46:ee:96:de brd ff:ff:ff:ff:ff:ff link-netnsid 9
inet6 fe80::24:46ff:feee:96de/64 scope link
valid_lft forever preferred_lft forever
298: vethc600360@if297: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 0a:ea:0f:fc:cb:a1 brd ff:ff:ff:ff:ff:ff link-netnsid 10
inet6 fe80::8ea:fff:fefc:cba1/64 scope link
valid_lft forever preferred_lft forever
300: veth0e54aa2@if299: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether 5e:59:0e:14:bd:ec brd ff:ff:ff:ff:ff:ff link-netnsid 11
inet6 fe80::5c59:eff:fe14:bdec/64 scope link
valid_lft forever preferred_lft forever
302: veth4c3be0e@if301: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether a6:ed:c7:aa:e4:eb brd ff:ff:ff:ff:ff:ff link-netnsid 12
inet6 fe80::a4ed:c7ff:feaa:e4eb/64 scope link
valid_lft forever preferred_lft forever
304: vethe39180c@if303: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-6697dc50ea30 state UP group default
link/ether a2:af:61:59:ce:a8 brd ff:ff:ff:ff:ff:ff link-netnsid 13
inet6 fe80::a0af:61ff:fe59:cea8/64 scope link
valid_lft forever preferred_lft forever
#
# logs
#
Sep 30 12:45:12 node-1 kernel: [2344084.198222] device eth1 left promiscuous mode
Sep 30 12:45:17 node-1 kernel: [2344088.451357] br0: port 4(veth5WQ7E1) entered disabled state
Sep 30 12:45:20 node-1 kernel: [2344092.026239] kauditd_printk_skb: 11 callbacks suppressed
Sep 30 12:45:20 node-1 kernel: [2344092.026242] audit: type=1400 audit(1601459120.759:396): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/dev/" pid=37489 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.032378] audit: type=1400 audit(1601459120.767:397): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/proc/sys/net/" pid=37491 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.035466] audit: type=1400 audit(1601459120.767:398): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/proc/sys/" pid=37492 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.038155] audit: type=1400 audit(1601459120.771:399): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/proc/sysrq-trigger" pid=37493 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.044738] audit: type=1400 audit(1601459120.779:400): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/sys/devices/virtual/net/" pid=37495 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.047507] audit: type=1400 audit(1601459120.779:401): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/sys/devices/virtual/net/" pid=37496 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.050152] audit: type=1400 audit(1601459120.783:402): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/proc/cpuinfo" pid=37497 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.053460] audit: type=1400 audit(1601459120.787:403): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/proc/diskstats" pid=37498 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.056565] audit: type=1400 audit(1601459120.791:404): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/proc/meminfo" pid=37499 comm="mount" flags="ro, remount"
Sep 30 12:45:20 node-1 kernel: [2344092.059235] audit: type=1400 audit(1601459120.791:405): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxc-test-1_</var/lib/lxc>" name="/proc/stat" pid=37500 comm="mount" flags="ro, remount"
Sep 30 12:49:30 node-1 kernel: [2344342.068192] br155: port 3(veth9DCBCY) entered disabled state
Sep 30 12:49:30 node-1 kernel: [2344342.068688] br0: port 4(veth5WQ7E1) entered disabled state
Sep 30 12:49:30 node-1 kernel: [2344342.069309] device veth9DCBCY left promiscuous mode
Sep 30 12:49:30 node-1 kernel: [2344342.069312] br155: port 3(veth9DCBCY) entered disabled state
Sep 30 12:49:30 node-1 kernel: [2344342.136177] device veth5WQ7E1 left promiscuous mode
Sep 30 12:49:30 node-1 kernel: [2344342.136180] br0: port 4(veth5WQ7E1) entered disabled state
As we can see, the pair of veth 327-328 (veth9DCBCY) is still alive over ~4-5min even after lxc-stop test-1
. The question is: Why? How to avoid this behavior?