Containers¶
Containers are LXC instances running on Proxmox nodes. For creating and managing containers, see the Web GUI Guide or Command Line Guide.
LDAP Authentication¶
Users in the ldapusers group can SSH into any container using their cluster credentials. Group memberships and password changes propagate automatically.
Container States¶
| State | Description |
|---|---|
| Running | Active and accessible via SSH/web |
| Stopped | Stopped but not deleted |
| Creating | Being provisioned |
| Failed | Creation or startup failed |
Volumes¶
Containers can attach persistent volumes — bind-mount directories whose data survives delete + recreate on the same hostname. Each volume has a name, a guest mount path, and a read-only or read-write mode. A container has only the volumes its creator attaches; nothing is mounted by default. See Volumes for the shared-storage requirement and backup caveats.
Service Exposure¶
Users can expose HTTP services from containers using external domains. Services are automatically configured with SSL/TLS certificates, reverse proxy routing, and DNS records.
HTTP services can optionally require authentication via the Require auth checkbox. When enabled, NGINX authenticates requests against the domain's oauth2-proxy server before proxying. Authenticated requests include identity headers (X-User, X-Preferred-Username, X-Email, X-Groups) forwarded to the backend — see Adding Authentication for how apps consume them. See External Domains — Authentication for configuration details.