Merge pull request 'docs(pxe-boot): fix NFS path, note nesting=1 requirement for LXC' (#77) from worktree-debian-pxe into main

Reviewed-on: #77
This commit is contained in:
2026-07-26 19:18:48 +00:00
+18 -6
View File
@@ -39,13 +39,25 @@ The host creates these directories with systemd tmpfiles:
/srv/pxe/tftp /srv/pxe/tftp
``` ```
`/srv/pxe/http/images` is a symlink to `/mnt/pxe-images`, which is an NFSv4.2 `/srv/pxe/http/images` is a symlink to `/mnt/pxe-images`, which is an NFS
mount of `server.sweet.home:/tank/proxmox/pxe-images` mount of `server.sweet.home:/tank/pxe-boot/images`
(`modules/pxe-boot/mount-pxe-images.nix`). Place large images there (ISOs, (`modules/pxe-boot/mount-pxe-images.nix`). Place large images there (ISOs,
disk images) rather than on the pxe-boot host's own root disk. For an LXC disk images) rather than on the pxe-boot host's own root disk. For an LXC
pxe-boot container the mount uses `nofail` (eager, non-blocking on server pxe-boot container the mount uses NFSv3+nolock with `nofail` (eager,
unavailability); for a Proxmox VM it uses `x-systemd.automount` (lazy, non-blocking on server unavailability); for a Proxmox VM it uses NFSv4.2
triggered on first access). with `x-systemd.automount` (lazy, triggered on first access).
When running as `lxc-pxe-boot`, the Proxmox container must have
`features: nesting=1,mount=nfs` (at minimum) in its Proxmox config. `nesting=1`
is required by systemd 260+ for credential isolation (user namespace creation
and internal move-mounts); without it, AppArmor denies both, and every
systemd service that uses `PrivateUsers`, `PrivateDevices`, or credential
passing fails on boot. `mount=nfs` allows the NFSv3 mount. Both are set
automatically by `scripts/proxmox/create-proxmox-resource.sh` (via
`PROXMOX_DEFAULT_LXC_FEATURES` in `scripts/env.sh` which defaults to
`nesting=1,keyctl=1,mount=nfs;nfs4`). If you ever change these features
manually via `pct set`, be sure to include both — `pct set` replaces the
entire features string, it does not append to it.
The HTTP iPXE chain is: The HTTP iPXE chain is:
@@ -121,7 +133,7 @@ The SystemRescue entry expects the source ISO at:
``` ```
Since `/srv/pxe/http/images` is the NFS-backed symlink, place the ISO on the Since `/srv/pxe/http/images` is the NFS-backed symlink, place the ISO on the
NFS share at `server.sweet.home:/tank/proxmox/pxe-images/systemrescue.iso`. NFS share at `server.sweet.home:/tank/pxe-boot/images/systemrescue.iso`.
The `stage-systemrescue.service` oneshot extracts that ISO into: The `stage-systemrescue.service` oneshot extracts that ISO into: