{
"meta": {
"title": "Data, paths and networking | ProxMenux",
"description": "How OCI manager Apps keeps the data of an OCI container: container disks, host directories, Rclone mounts, addresses and private networks."
},
"header": {
"title": "Data, paths and networking",
"description": "What lives in the rootfs, what survives its replacement, how data is shared between containers and how each container gets its address.",
"section": "OCI manager Apps"
},
"sections": [
{
"id": "intro",
"blocks": [
{
"calloutInfo": {
"title": "Persistence is decided before the LXC exists",
"body": "The volumes published by the image and by its Compose file are read before the container is created. Every path that has to survive an update becomes a mount point independent of the rootfs, so the rootfs only holds what belongs to the image and can be replaced."
}
}
]
},
{
"id": "questions",
"title": "What the installer asks",
"intro": "The template supplies the paths the application needs. Each one is placed on a container disk or on a host directory, and more paths can be added before the summary.",
"blocks": [
{
"steps": {
"items": [
{ "title": "Required paths", "body": "/config, /data, libraries, downloads and every volume the application declares are listed." },
{ "title": "Location", "body": "Each path is placed on a disk of the container or on an existing host directory." },
{ "title": "Storage and size", "body": "A container disk is created on a Proxmox VE storage, local-lvm by default, with the size given. It appears as vm-VMID-disk-N and is attached as mpN." },
{ "title": "Host directory", "body": "A host directory is given by its path. A directory that does not exist is created, owned by the user the container maps." },
{ "title": "Additional paths", "body": "More pairs of host path or volume and container path can be added before installing." },
{ "title": "Summary", "body": "The complete mapping is shown before the CT is created and is stored in its instance contract." }
]
}
}
]
},
{
"id": "options",
"title": "The two persistent locations",
"blocks": [
{
"table": {
"headers": ["Property", "Container disk", "Host directory"],
"rows": [
["In the configuration", "mpN: STORAGE:vm-VMID-disk-N,mp=/config,backup=1,size=16G", "mpN: /mnt/oci-shared/media,mp=/data/media"],
["Container backup (vzdump)", "Included, with backup=1", "Not included"],
["Size", "Fixed; grown with a resize of the mount point", "The free space of the host filesystem or dataset"],
["Other containers", "Mounted only by its own container", "The same directory can be mounted in several containers"],
["Snapshots and restore", "Managed by Proxmox VE together with the CT", "Managed on the host storage"],
["Removing the application", "Deleted with the container", "Kept, with its content"],
["Moving the CT to another node", "Moves with the CT", "The same path has to exist on the other node"]
]
}
},
{
"p": "The rootfs is reserved for the binaries and the content of the image. An update or a recreation replaces it without touching either kind of mount point."
}
]
},
{
"id": "example",
"title": "Example: a container with both locations",
"blocks": [
{
"code": {
"title": "Jellyfin installed as CT 151 on local-lvm (excerpt)",
"code": "rootfs: local-lvm:vm-151-disk-0,size=8G\n# Container disk, part of the CT backup\nmp0: local-lvm:vm-151-disk-1,mp=/config,backup=1,size=16G\n\n# Host directory, outside the CT backup\nmp1: /mnt/oci-shared/media,mp=/data/media"
}
},
{
"p": "An update or a recreation replaces only the rootfs: mp0 keeps users, libraries and settings, and mp1 keeps showing the same media. Restoring the CT backup brings back /config; the media directory is restored, if needed, from the backup of the host storage."
},
{
"flow": {
"nodes": [
{ "label": "Contract", "detail": "/config" },
{ "label": "Location", "detail": "container disk\nor host directory" },
{ "label": "LXC", "detail": "always /config\nfor the application" }
],
"caption": "The application sees the path the image publishes; only where it is stored changes."
}
}
]
},
{
"id": "shared",
"title": "One host directory, several containers",
"blocks": [
{
"mermaid": {
"chartCode": "flowchart TB\n H[\"{{host}}
/mnt/oci-shared/media\"]\n H --> Q[\"qBittorrent
/data\"]\n H --> J[\"Jellyfin
/data\"]\n H --> R[\"Radarr / Sonarr
/data\"]\n Q -. \"{{config}}\" .-> QV[(\"/config mpN\")]\n J -. \"{{config}}\" .-> JV[(\"/config mpN\")]\n R -. \"{{config}}\" .-> RV[(\"/config mpN\")]",
"labels": { "host": "Host directory", "config": "own configuration" }
}
},
{
"p": "Each container keeps its configuration on its own disk. The library or the downloads are one host directory mounted at the same internal path in every container, so a path that one application writes is the same path another one reads."
}
]
},
{
"id": "rclone",
"title": "Cloud storage through the Rclone application",
"intro": "The Rclone application of the catalog offers, besides its installation, Enable a mount on an existing Rclone OCI container. It mounts a remote already created and authorised in the Rclone web UI and publishes it on the host, where other containers can use it as a host directory.",
"blocks": [
{
"steps": {
"items": [
{ "title": "Container and remote", "body": "The VMID of the Rclone container, the exact name of the remote and, optionally, a path inside it." },
{ "title": "Mount name and cache", "body": "The name of the mount and the VFS cache mode: off, minimal, writes or full (default)." },
{ "title": "Published views", "body": "A common root, /mnt/oci-shared by default, holds a read/write view in /mnt/oci-shared/remotes/NAME and a read-only view in /mnt/oci-shared/remotes-ro/NAME." },
{ "title": "Activation", "body": "After a confirmation, the CT is stopped, its start command and a Proxmox VE hookscript are set, and it is started again. The operation waits until both views are mounted on the host." }
]
}
},
{
"calloutInfo": {
"title": "If the mount does not come up",
"body": "The previous configuration of the container is restored and it is started again, so a failed activation leaves Rclone as it was."
}
}
]
},
{
"id": "network",
"title": "Addresses and networks",
"intro": "A single application needs an address. A multi-container application also needs a stable network between its members.",
"blocks": [
{
"cards": {
"items": [
{ "icon": "network", "title": "Single application", "body": "Bridge and DHCP or a fixed CIDR address are chosen. The LXC has an address of its own and the summary shows the complete URLs of the services." },
{ "icon": "waypoints", "title": "Multi-container application", "body": "A free subnet is found, a persistent private bridge is created and each member (application, database, cache) gets a fixed address on it." }
]
}
},
{
"flow": {
"nodes": [
{ "label": "LAN", "detail": "reachable address\nmain service only" },
{ "label": "Main LXC", "detail": "web / API\nLAN + private network" },
{ "label": "Private network", "detail": "PostgreSQL · Valkey · ML\nfixed addresses" }
],
"caption": "Dependencies talk over the private network and have no address on the LAN."
}
},
{
"p": "The stack contract stores bridge, subnet, addresses and the relations between services. Updating or recreating a member reuses the same topology. ProxMenux Monitor opens the main container at its LAN address, not at its address on the private network."
}
]
},
{
"id": "ownership",
"title": "Ownership",
"blocks": [
{
"list": {
"items": [
"New directories are created with the UID and GID the unprivileged LXC maps.",
"Existing directories are not re-owned recursively.",
"Sockets, system files and sensitive paths are not offered as generic host directories."
]
}
}
]
},
{
"id": "backup",
"title": "What a container backup contains",
"blocks": [
{
"table": {
"headers": ["Element", "In the CT vzdump", "Where it is kept"],
"rows": [
["OCI rootfs", "Yes", "The CT backup; it can also be rebuilt from the image and the contract"],
["Container disk with backup=1", "Yes", "The CT backup"],
["Host directory", "No", "The backup of the host storage"],
["Instance contract", "No", "/usr/local/share/proxmenux/oci/instances/VMID/ on the host"],
["Multi-container application", "Each member in its own backup", "The backups of every member, plus the stack contract and its bridge on the host"]
]
}
}
]
}
]
}