SYSTEMD-NSPAWN(1) systemd-nspawn SYSTEMD-NSPAWN(1) (NAME) systemd-nspawn - (Namespace) (SYNOPSIS) systemd-nspawn [OPTIONS...] [COMMAND [ARGS...]] systemd-nspawn --boot [OPTIONS...] [ARGS...] (DESCRIPTION) systemd-nspawn (namespace) . chroot(1) IPC . systemd-nspawn --directory= . --machine= /var/lib/machines/ . chroot(1) systemd-nspawn . systemd-nspawn /sys/ /proc/sys/ /sys/fs/selinux/ . . . . (user namespaces) (sandbox) . --private-users= . dnf(8) debootstrap(8) pacman(8) systemd-nspawn . <<>> . systemd-nspawn /usr/lib/os-release /etc/os-release ( os-release(5) ). . systemd-nspawn . systemd-nspawn@.service . systemd-nspawn . --boot systemd-nspawn . . machinectl(1) . systemd-nspawn@.service . .nspawn . systemd.nspawn(5) . systemd-nspawn@.service . systemd-nspawn /dev/ /run/ . . systemd-nspawn . PID . login shell machinectl(1) . systemd-nspawn Container Interface[1] . systemd-nspawn systemd-machined(8) . (UNPRIVILEGED OPERATION) systemd-nspawn . . : o ( --image=). ( --directory=) UID <<>> (foreign) . o --private-network --network-veth . systemd- mountfsd.service(8) systemd-nsresourced.service(8) . (OPTIONS) --boot (init) . COMMAND . --boot (shell) . : -q, --quiet . nspawn . 209. --settings=MODE systemd-nspawn .nspawn . override trusted . () ( --machine= ) .nspawn /etc/systemd/nspawn/ /run/systemd/nspawn/ . . . . .nspawn . . .nspawn systemd.nspawn(5) . override : .nspawn . trusted /etc/systemd/nspawn/ /run/systemd/nspawn/ . .nspawn . 226. --cleanup . systemd-nspawn . -M/--machine= -D/--directory= -i/--image= . 257. (Image Options) -D, --directory= . --directory= --image= --machine= . << >> machinectl(1) . ".v/" systemd.v(7) . --directory= --image= --machine= . --image= . --template= "btrfs" . ( --directory= ) "btrfs" ( ) ( ) . "btrfs" (copy-on-write) . "btrfs" ( "btrfs" ) ( 'reflink' -- ) . . --image= --ephemeral . . 219. -x, --ephemeral . --template= . . -- --template= -- 'reflink' ( "btrfs" "xfs" ) ( "ext4") . . . --volatile= ( ) . 219. -i, --image= . . : o MBR 0x83 . o (GPT) 0fc63daf-8483-4772-8e79-3d69d8477de4. o (GPT) . GPT (home) / . UAPI.2 Discoverable Partitions Specification[2] . o . GPT EFI (ESP) /efi ( /boot ) . LUKS . GPT --root-hash= dm-verity . ( ) dm-verity --root-hash= --verity-data= ( --root-hash-sig=) . swap . --directory= --template= . ".v/" systemd.v(7) . 211. --image-policy=policy systemd.image-policy(7) . --image= ( ) . "root=verity+signed+encrypted+unprotected+absent:usr=verity+signed+encrypted+unprotected+absent:home=encrypted+unprotected+absent:srv=encrypted+unprotected+absent:esp=unprotected+absent:xbootldr=unprotected+absent:tmp=encrypted+unprotected+absent:var=encrypted+unprotected+absent" swap . 254. --mstack= . systemd.mstack(7) . "overlayfs" bind . 260. --oci-bundle= OCI OCI Runtime Specification[3] . .nspawn JSON OCI ( ). 242. --read-only ( ) . --bind= --tmpfs= . . --volatile= . . . --volatile, --volatile=MODE (volatile) . yes . "tmpfs" /usr/ ( ). state /var/ "tmpfs" ( ). overlay "overlayfs" tmpfs . no () ( --read-only ). ( /var/ state) -- ( EFI /efi/ /boot/ ) ( --bind= ). --volatile=overlay /efi/ /boot/ --volatile=state --bind=/etc/foobar /etc/ /etc/foobar . --ephemeral . . --tmpfs= --overlay= . . "systemd.volatile=" . kernel- command-line(7) . yes state /usr/ /var/ ( "--volatile=yes" /etc/) . /bin/ /lib/ ( ) /usr/ ( ) "--volatile=yes" . overlay "overlayfs" . 216. --root-hash= (dm-verity) . ( ) dm-verity . ( ) ( SHA256). "user.verity.roothash" ( xattr(7) ) . ( ) .roothash ( .raw ) . . /usr/ Verity . "user.verity.usrhash" .usrhash . /usr/ . RootHash= systemd.exec(5) . 233. --root-hash-sig= PKCS7 --root-hash= . RootHashSignature= systemd.exec(5) . 246. --verity-data= (dm-verity) . dm-verity . . .verity ( .raw verity ) verity . 246. --pivot-root= / (pivot) . : -- / . / / . . ostree(1). initrd PID 1 . 233. (Execution Options) -a, --as-pid2 (PID) PID 1 (init) . --boot PID 1 PID 1 . (reap) sysvinit ( : SIGINT SIGTERM SIGHUP ). --as-pid2 (stub init) PID 1 PID 2 ( ). . PID 1 . : init PID 1 . --boot . 229. -b, --boot (init) PID 1 . init . --as-pid2 . --as-pid2 ( ) : Table 1. Invocation Mode +---------------------------+--------------------------------+ | | | +---------------------------+--------------------------------+ | --as-pid2 | | | --boot | | | | | | | | | | | | | | | | PID 1 | | | | | | | | | . | +---------------------------+--------------------------------+ |--as-pid2 | | | | | | | | | | | | | | | | | | | PID 2 | | | | | | | | | . | | | | | | | | | | | | PID 1 | | | | | | . | +---------------------------+--------------------------------+ |--boot | | | | | | | | | | | | | PID 1 | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | | | . | +---------------------------+--------------------------------+ systemd-nspawn@.service --boot . --boot PID 1 : "KEY=VALUE" "KEY" "." PID 1 ( "-" "_" --setenv= ) ( "systemd.*=") . --chdir= . . 229. -E NAME[=VALUE], --setenv=NAME[=VALUE] . . . "=" VALUE . 209. -u, --uid= . systemd-nspawn . --user= . . -u systemd-nspawn . --uid= (: --set-credential= --load-credential=) --no-new-privileges=yes --boot --as-pid2 . --kill-signal= SIGTERM nspawn PID 1 . --boot SIGRTMIN+3 ( init systemd SIGRTMIN+3 ). --boot SIGKILL . signal(7) . 220. --notify-ready= . --notify-ready= . false systemd-nspawn "READY=1" . true "READY=1" . sd_notify(3) . false . ( systemd- vmspawn(1) true .) systemd-nspawn $NOTIFY_SOCKET ( sd_notify(3) ) "FDSTORE=1" "FDSTOREREMOVE=1" ( "FDNAME=") . ( kexec LUO ) FileDescriptorStoreMax=/FileDescriptorStorePreserve=yes systemd-nspawn . File Descriptor Store[4] . 231. --suppress-sync= . true . sync(2) fsync() syncfs() O_SYNC/O_DSYNC open(2) . ( ). - . false . 250. (System Identity Options) -M, --machine= . ( machinectl(1) ) (hostname) ( ). --ephemeral . . 202. --hostname= . . --machine= . . . --machine= . --hostname= --machine= . 239. --uuid= (UUID) . init /etc/machine-id . /etc/machine-id . (Property Options) -S, --slice= machine.slice (slice) . (scope unit) --keep-unit . 206. --property= . --keep-unit . systemctl set-property . . 220. --register= systemd-machined(8) . "auto" "auto" . ( : PID 1) machinectl(1) ps(1) . "no" . "auto" . 209. --keep-unit systemd-nspawn . --register=yes systemd-machined(8) . systemd-nspawn systemd-nspawn . . --keep-unit --slice= --property= . --keep-unit --register=no systemd-machined . 209. (User Namespacing Options) --private-users= . (UID GID) . UID/GID ( 0 ) UID/GID ( UID/GID 65536 ). : 1. . UID/GID UID/GID . UID/GID . 2. "yes" . UID/GID . UID/GID . ACL UID/GID . UID/GID UID/GID . 3. "pick" . UID/GID . UID/GID . UID/GID "yes" . ( UID/GID ) UID/GID - - UID/GID UID/GID . --private-users-ownership=auto ( ) . . UID/GID ( ) . ( UID/GID ). 4. "no" . systemd-nspawn . ( systemd-nspawn@.service .) . 5. "identity" (identity mapping) UID/GID . --private-users=0:65536 . UID/GID ( UID/GID ) (process capabilities) UID . . 6. "managed" managed () UID systemd- nsresourced.service(8) . . 64K UID . UID/GID UID/GID . UID/GID . UID/GID UID/GID . --private-users=pick . GID UID . --private-users=managed ( --private-users=pick ) . UID/GID /etc/passwd /etc/group . --private-users-ownership= . UID ( ) . UID/GID UID/GID . "managed" UID . 220. --private-users-ownership= UID GID UID/GID --private-users= ( ) . "off" ( ) "chown" ( chown() ) "map" ( UID 0 UID ) "foreign" ( UID ) "auto" "map" "foreign" "chown" . "chown" UID/GID ( ). . ACL . "foreign" "map" UID/GID . . --private-users-ownership=auto --private-users=pick . . --shift systemd-dissect(1) UID/GID UID/GID systemd-nspawn . 230. --private-users-delegate= . 64K UID/GID . : ( UID/GID ) UID/GID systemd-nsresourced.service(8) . --private-users=managed systemd-nsresourced.service(8) . . 0 . Varlink systemd- nsresourced.service(8) (/run/systemd/io.systemd.NamespaceResource) /run/systemd/userdb/ /run/varlink/registry/ bind-mount . systemd-nsresourced . 260. -U --private-users=pick --private-users-ownership=auto --private-users=no . systemd-nspawn@.service -U . : UID 0 --private-users-ownership=chown ( -U) : systemd-nspawn ... --private-users=0 --private-users-ownership=chown 230. (Networking Options) --private-network . loopback --network-interface= --network-veth . CAP_NET_ADMIN . --drop-capability= . ( ) . --network-interface= . . . --network-interface= --private-network . . . systemd-nspawn@.service (drop-in) ( /etc/systemd/system/systemd-nspawn@foobar.service.d/50-network.conf) : [Unit] Wants=sys-subsystem-net-devices-ens1.device After=sys-subsystem-net-devices-ens1.device "ens1" . . 209. --network-macvlan= "macvlan" . . "macvlan" MAC . "mv-" . --network-macvlan= --private-network . . --network-interface= . 211. --network-ipvlan= "ipvlan" . . "ipvlan" "macvlan" MAC . "iv-" . --network-ipvlan= --private-network . . --network-interface= . 219. -n, --network-veth ("veth") . ( --machine= ) "ve-" . "host0" . --network-veth --private-network . systemd- networkd.service(8) /usr/lib/systemd/network/80-container-ve.network DHCP IP . /usr/lib/systemd/network/80-container-host0.network DHCP . systemd-networkd IP . --network-veth systemd-nspawn@.service . . . . systemd-nspawn . . ( systemd.net-naming-scheme(7) ). --network-veth-extra= -- --network-bridge= . 209. --network-veth-extra= . . . --network-veth -- -- . --network-bridge= --network-veth-extra= . 228. --network-bridge= --network-veth (Ethernet bridge) . . --network-bridge= --network-veth . "vb-" "ve-" . ( ). --network-interface= . 209. --network-zone= ("veth") . "vz-" . . . / --network-bridge= . <<>> (zone) . . . ( "vz-" ) --network-zone= . systemd- networkd.service(8) /usr/lib/systemd/network/80-container-vz.network DHCP IP . --network-zone= . 230. --network-namespace-path= . ( bind-mounted) /proc/$PID/ns/net . . /run/netns ip-netns(8) --network-namespace-path=/run/netns/foo. --private-network --network-interface= . 236. -p, --port= IP IP . ( "tcp" "udp") 1 65535 1 65535 . "tcp" . . --network-veth --network-zone= --network-bridge=. 219. (Security Options) --capability= . capabilities(7) . : CAP_AUDIT_CONTROL, CAP_AUDIT_WRITE, CAP_CHOWN, CAP_DAC_OVERRIDE, CAP_DAC_READ_SEARCH, CAP_FOWNER, CAP_FSETID, CAP_IPC_OWNER, CAP_KILL, CAP_LEASE, CAP_LINUX_IMMUTABLE, CAP_MKNOD, CAP_NET_BIND_SERVICE, CAP_NET_BROADCAST, CAP_NET_RAW, CAP_SETFCAP, CAP_SETGID, CAP_SETPCAP, CAP_SETUID, CAP_SYS_ADMIN, CAP_SYS_BOOT, CAP_SYS_CHROOT, CAP_SYS_NICE, CAP_SYS_PTRACE, CAP_SYS_RESOURCE, CAP_SYS_TTY_CONFIG. --private-network CAP_NET_ADMIN . "all" . "help" . (bounding set) (ambient capabilities) --ambient-capability= . 186. --drop-capability= . ( ) . "help" . --ambient-capability= . 209. --ambient-capability= . "all" . --capability= --drop-capability= . . ( --boot ) . "help" . 248. --no-new-privileges= . PR_SET_NO_NEW_PRIVS . . "setuid" . prctl(2) . 239. --system-call-filter= . ( "@" syscall-filter systemd- analyze(1) ). . "~" . . ( "~" "~") . systemd-nspawn ( !) "~" . --capabilities= . 235. --restrict-address-families= . AF_INET AF_INET6 AF_UNIX . "~" ( ). "none" . . . . systemd AF_INET AF_INET6 AF_UNIX . --restrict-address-families= ( ) RestrictAddressFamilies= .nspawn . 261. -Z, --selinux-context= SELinux . 209. -L, --selinux-apifs-context= SELinux API . 209. (Resource Options) --rlimit= POSIX . "LIMIT=SOFT:HARD" "LIMIT=VALUE" LIMIT RLIMIT_NOFILE RLIMIT_NICE . SOFT HARD . VALUE . "infinity" . . . setrlimit(2) . (PID 1) init . RLIMIT_NPROC. ( --private-users= ) . . : "--rlimit=RLIMIT_NOFILE=8192:16384". 239. --oom-score-adjust= OOM (" ") . /proc/self/oom_score_adj . proc(5) . -1000...1000 . 239. --cpu-affinity= (CPU affinity) . ( ) . sched_setaffinity(2) . 239. --personality= ("personality") uname(2) . "x86" "x86-64" . . . 209. (Integration Options) --resolv-conf= /etc/resolv.conf ( DNS ) . "off" "copy-host" "copy-static" "copy-uplink" "copy-stub" "replace-host" "replace-static" "replace-uplink" "replace-stub" "bind-host" "bind-static" "bind-uplink" "bind-stub" "delete" "auto" . "off" /etc/resolv.conf bind-mount . "copy-host" /etc/resolv.conf ( ). "replace-host" . "bind-host" bind- mount . "copy-static" "replace-static" "bind-static" resolv.conf systemd-resolved.service(8) ( : /usr/lib/systemd/resolv.conf) bind-mount . "copy-uplink" "replace-uplink" "bind-uplink" resolv.conf systemd-resolved.service ( : /run/systemd/resolve/resolv.conf) bind-mount . "copy-stub" "replace-stub" "bind-stub" (stub) resolv.conf systemd-resolved.service ( : /run/systemd/resolve/stub-resolv.conf) bind-mount . "delete" /etc/resolv.conf . "auto" ( --private-network ) . systemd-resolved.service resolv.conf /etc/resolv.conf . bind-mount . DNS "copy-..." "replace-..." . "bind" /etc/resolv.conf bind-mount ( bind-mount ). bind-mount ( ). "auto" . 239. --timezone= /etc/localtime ( ) . "off" "copy" "bind" "symlink" "delete" "auto" . "off" /etc/localtime bind-mount . "copy" /etc/localtime . "bind" bind-mount . "symlink" /etc/localtime . "delete" . "auto" /etc/localtime "symlink" "copy" "bind" . "auto" . 239. --link-journal= . ( ) . "no" "host" "try-host" "guest" "try-guest" "auto" . "no" . "host" ( /var/log/journal/machine-id) bind-mount . "guest" ( /var/log/journal/machine-id) . "try-host" "try-guest" --ephemeral . "auto" () /var/log/journal bind-mount . . "guest" "host" "auto" . systemd-nspawn@.service --link-journal=try-guest . 187. -j --link-journal=try-guest . 187. --forward-journal= systemd-journal-remote(8) bind-mount . systemd-journald(8) journal.forward_to_socket . . ".journal" . 261. --forward-journal-max-use=BYTES, --forward-journal-keep-free=BYTES, --forward-journal-max-file-size=BYTES, --forward-journal-max-files=N systemd-journal-remote(8) . journal-remote.conf(5) . 261. (Mount Options) --bind=, --bind-ro= bind-mount . : -- -- . "+" . . bind-mount . /var/tmp/ . . . --bind-ro= bind . "\:" . bind- mount . . rbind norbind bind-mount . rbind . noidmap idmap rootidmap owneridmap (ID mapping) . idmap rootidmap owneridmap / . noidmap . x UID y UID p UID bind- mount : o noidmap z 0 ... y x + z x ... x + y . nobody . o idmap z UID 0 ... y z 0 ... y . nobody . o rootidmap 0 p . nobody . o owneridmap p . nobody . . rootidmap owneridmap bind-mount . --private-users nobody . UID 65534 (nobody) . bind-mount --bind-ro= . "idmap" . 198. --bind-user= (home) bind . . bind . : 1. (idmapped mount) /run/host/home/ bind-mount UID/GID UID/GID . 2. JSON /run/userdb/ . UID/GID . NSS nss-systemd(8) / . . ( ). UID/GID . . UID/GID ( --bind-user=) <<>> . / systemd 249 nss-systemd nsswitch.conf . nss- systemd(8) . . ( yescrypt "$y$") . bind . UID/GID / . /etc/passwd /etc/group . 249. --bind-user-shell= --bind-user= bind . . o false () bind . bind . o true bind . o bind . : . --bind-user= . 258. --bind-user-group=NAME --bind-user= bind . . : . --bind-user= . 259. --inaccessible= . ( ) . . . 242. --tmpfs= tmpfs . tmpfs ( 0755 root/root ) ( ). "\:" . . --volatile= (stateless) . 214. --overlay=, --overlay-ro= (overlay) . . "\:" . overlay . . --overlay= --overlay-ro= overlay . overlay . overlay . . "+" . . /var/tmp/ . . . "--overlay=+/var::/var" /var/ . . overlay Overlay Filesystem[5] . overlay . . "workdir=" overlay () . ( ). "lowerdir=" . overlay . --volatile= . 220. / (Input/Output Options) --console=MODE /dev/console . interactive read-only passive pipe autopipe . interactive pseudo-TTY /dev/console . systemd-nspawn . read-only . passive pseudo TTY . pipe pseudo TTY systemd-nspawn -- -- . autopipe systemd-nspawn interactive pipe. systemd-nspawn interactive read-only. pipe /dev/console . init init /dev/console . (shell pipelines) . pseudo TTY (EOF) . pipe . TTY API TIOCSTI . pipe // . 242. --pipe, -P --console=pipe . 242. --background=COLOR ANSI . ANSI X3.64 SGR "40" "41" ... "47" "48;2;..." "48;5;...". ANSI Escape Code (Wikipedia)[6] . . 256. (Credentials) --load-credential=ID:PATH, --set-credential=ID:VALUE . LoadCredential= SetCredential= . systemd.exec(5) . : systemd-nspawn systemd LoadCredential=/SetCredential= . systemd PID 1 . . . --set-credential= C ( "\n" "\x00" NUL). ! systemd-sysusers.service(8) systemd-firstboot(1) (locale) . --volatile=yes /etc/ . . : # systemd-nspawn -i image.raw \ --volatile=yes \ --set-credential=firstboot.locale:de_DE.UTF-8 \ --set-credential=passwd.hashed-password.root:'$y$j9T$yAuRJu1o5HioZAGDYPU5d.$F64ni6J2y2nNQve90M/p0ZP0ECP/qqzipNyaY9fjGpC' \ -b image.raw /etc/ /var/ . systemd-firstboot.service . 247. (Other) --system, --user . machined . root --system --user . : --user --user=NAME ( --uid=) . --user "--" . 261. --no-pager . -h, --help . --version . --no-ask-password . (HOTKEYS) ( --console=interactive) . . Ctrl-] Ctrl-] Ctrl-] . Ctrl-] Ctrl-] r (reboot) . 258. Ctrl-] Ctrl-] p (shutdown) . 258. (ENVIRONMENT) $SYSTEMD_LOG_LEVEL ( ). . ( ) : emerg alert crit err warning notice info debug 0...7. syslog(3) . console syslog kmsg journal ( SYSTEMD_LOG_LEVEL=debug,console:info debug info ). . $SYSTEMD_LOG_COLOR . true tty . journalctl(1) . $SYSTEMD_LOG_TIME . true . journalctl(1) . $SYSTEMD_LOG_LOCATION . true . . . $SYSTEMD_LOG_TID . true (TID) . . . $SYSTEMD_LOG_TARGET . console ( tty ) console-prefixed ( tty "facility" syslog(3) ) kmsg ( ) journal ( ) journal-or-kmsg ( kmsg) auto ( ) null ( ). $SYSTEMD_LOG_RATELIMIT_KMSG kmsg . . "true" . systemd kmsg . $SYSTEMD_PAGER, $PAGER --no-pager . $SYSTEMD_PAGER $PAGER . $SYSTEMD_PAGER $PAGER less(1) more(1) . . "cat" --no-pager . : $SYSTEMD_PAGERSECURE $SYSTEMD_PAGER $PAGER ( "cat" "") . $SYSTEMD_LESS less ( "FRSXMK"). : K Ctrl+C . less Ctrl+C . $SYSTEMD_LESS "K" less Ctrl+C . X termcap . . . $LESS less systemd . less(1) . $SYSTEMD_LESSCHARSET less ( "utf-8" UTF-8 ). $LESSCHARSET less systemd . $SYSTEMD_PAGERSECURE less(1) <<>> . sudo(8) pkexec(1) . . << >> ( ). << >> --no-pager PAGER=cat . . true << >> . << >> LESSSECURE=1 . less(1) << >> . false . SYSTEMD_PAGERSECURE=0 . $SYSTEMD_PAGERSECURE systemd << >> . << >> UID geteuid(2) sd_pid_get_owner_uid(3) sudo(8) ( $SUDO_UID [7]). SYSTEMD_PAGERSECURE=1 << >> . . $SYSTEMD_PAGERSECURE . $SYSTEMD_PAGER $PAGER $SYSTEMD_PAGERSECURE . $SYSTEMD_COLORS . () systemd . $COLORTERM "truecolor" "24bit" $NO_COLOR $TERM . true $NO_COLOR . false . "16", "256", "24bit" ANSI . "auto-16", "auto-256", "auto-24bit" $TERM . $SYSTEMD_URLIFY . . systemd $TERM . (EXAMPLES) . TAR # importctl pull-tar -mN https://cloud-images.ubuntu.com/jammy/current/jammy-server-cloudimg-amd64-root.tar.xz # systemd-nspawn -M jammy-server-cloudimg-amd64-root .tar systemd-nspawn(1) . . # dnf -y --releasever=44 --installroot=/var/lib/machines/f44 \ --use-host-config --setopt=install_weak_deps=0 \ --repo=fedora --repo=updates install \ passwd dnf fedora-release nano util-linux systemd systemd-networkd # systemd-nspawn -bD /var/lib/machines/f44 ( dnf <= 4 --use-host-config .) /var/lib/machines/f44 . /var/lib/machines/ systemd-nspawn -M f44 . . # debootstrap unstable ~/debian-tree/ # systemd-nspawn -D ~/debian-tree/ (unstable) ~/debian-tree/ . debootstrap Debian[8] Ubuntu[9] . (mirror) debootstrap(8) . . # pacstrap -c ~/arch-tree/ base # systemd-nspawn -bD ~/arch-tree/ ~/arch-tree/ . . OpenSUSE Tumbleweed # zypper --root=/var/lib/machines/tumbleweed ar -c \ https://download.opensuse.org/tumbleweed/repo/oss tumbleweed # zypper --root=/var/lib/machines/tumbleweed refresh # zypper --root=/var/lib/machines/tumbleweed install --no-recommends \ systemd shadow zypper openSUSE-release vim # systemd-nspawn -M tumbleweed passwd root # systemd-nspawn -M tumbleweed -b . # systemd-nspawn -D / -xb . . . SELinux # chcon system_u:object_r:svirt_sandbox_file_t:s0:c0,c1 -R /srv/container # systemd-nspawn -L system_u:object_r:svirt_sandbox_file_t:s0:c0,c1 \ -Z system_u:system_r:svirt_lxc_net_t:s0:c0,c1 -D /srv/container /bin/sh . OSTree # systemd-nspawn -b -i ~/image.raw \ --pivot-root=/ostree/deploy/$OS/deploy/$CHECKSUM:/sysroot \ --bind=+/sysroot/ostree/deploy/$OS/var:/var (EXIT STATUS) . (SEE ALSO) systemd(1), systemd.nspawn(5), chroot(1), dnf(8), debootstrap(8), pacman(8), zypper(8), systemd.slice(5), machinectl(1), importctl(1), systemd-mountfsd.service(8), systemd-nsresourced.service(8), systemd.mstack(7), btrfs(8) (NOTES) 1. Container Interface https://systemd.io/CONTAINER_INTERFACE 2. UAPI.2 Discoverable Partitions Specification https://uapi- group.org/specifications/specs/discoverable_partitions_specification 3. OCI Runtime Specification https://github.com/opencontainers/runtime-spec/blob/master/spec.md 4. File Descriptor Store https://systemd.io/FILE_DESCRIPTOR_STORE 5. Overlay Filesystem https://docs.kernel.org/filesystems/overlayfs.html 6. ANSI Escape Code (Wikipedia) https://en.wikipedia.org/wiki/ANSI_escape_code#SGR_(Select_Graphic_Rendition)_parameters 7. $SUDO_UID . 8. Debian https://www.debian.org 9. Ubuntu https://www.ubuntu.com 10. Arch Linux https://www.archlinux.org 11. OpenSUSE Tumbleweed https://software.opensuse.org/distributions/tumbleweed systemd 261.3 SYSTEMD-NSPAWN(1)