User namespace work

This proposal has been accepted as a session.


One Line Summary

Current state and expected timeline for completion of unprivileged containers


The goal in lxc is for unprivileged users to be able to safely create and use containers.

It will begin by explaining the user namespace functionality, the subuid shadow extensions, and the pieces already implemented and those needed in lxc to enable the unprivileged container use.


