It’s perfectly fine for a user to have multiple id map entries in /etc/subuid and /etc/subgid, there are in fact no other ways to indicate the ability to use a single uid/gid outside of the main range.
Thank you for the quick reply. Has raw.idmap been replaced by lxc.idmap then? How would I say something like “Map all UID’s to UID 1000”? The following doesn’t seem right:
lxc.idmap = u 0 1000 1
That seems like it would only map 1 UID (0) in the container to UID 1000 on my host.
raw.idmap is use by LXD to generate lxc.idmap, it’s a much more user friendly format which is also integrated with LXD’s own idmap. The format for raw.idmap is covered in the id mapping part of our documentation.