Does a VM need to be offline to add a proxy device in NAT mode?

I can’t pretend to understand everything that happens under the hood when I create proxy rules for VMs but I had a feeling it was mostly nftable stuff on the host. However when adding new proxy devices I get a Device cannot be added when instance is running. Is this strictly required? Is there a way around this by any chance?

If it’s just a standard NAT rule, no, we should be able to apply it live.

We’re pretty conservative on what’s allowed to be changed live on VMs, this one feels like it would be a pretty easy thing to allow.

Can you file an issue at Issues · lxc/lxd · GitHub ?

