Guide 14 of 25 · intermediate

Create a First Proxmox Container and Respect Its Boundaries

Run a disposable LXC service while understanding shared-kernel risk.

Source-verified · Not lab-testedOfficial sources checked 2026-09-29. No PebbleRack hardware compatibility claim.

Outcome

You will create a small unprivileged Linux container and understand when to use a VM instead. Containers use the host kernel; they are not interchangeable with a full VM and should not host untrusted users simply because they are light.

Before you start

Use an existing supported Proxmox host with known storage and bridge settings. Pick a disposable service, such as a local test web server, with no personal data. Read Proxmox's container security considerations. If you need a different kernel, unknown-user isolation, or complex device access, choose a VM. Record an unused container ID and resource limits.

Steps

  1. Fetch a trusted template. In storage that supports container templates, open CT Templates → Templates and choose a maintained, supported Linux distribution template. Proxmox also offers a template utility and additional template sources; for this first exercise, keep the source and version simple and record them.
  2. Create an unprivileged container. Select Create CT, enter the unused ID and name, select Unprivileged container, and supply authentication according to the UI. This setting changes how container IDs map to host IDs; it is a useful default but does not make the container as isolated as a VM. Do not toggle privileged mode merely to make an application install succeed.
  3. Choose storage and limits. Select the planned container-capable storage and a modest root disk, CPU, and memory limit. A container can consume host resources, so leave headroom. Attach it to the intended bridge and use a documented DHCP reservation or static IP. Do not add host mount points or physical devices in the first exercise.
  4. Start and inspect. Open the container console, log in, check the OS version and network address, and install routine package updates. If you install a simple service, bind it only to the intended LAN and confirm it is reachable from a trusted client.
  5. Keep boundaries visible. Proxmox documents AppArmor, control groups, namespaces, and security limitations. Avoid weakening those controls to solve an unexplained error. If software demands privileged mode, host filesystem mounts, or kernel modules, reconsider the workload and test a VM instead.
  6. Record the result. Note container ID, template/version, privilege setting, root disk store, resource limits, bridge, IP, and why a container was acceptable. Add it to the backup plan only after confirming how its data volumes are included.

Check it worked

The container starts after a stop/start cycle, receives the intended network address, installs updates, and shows Unprivileged in its configuration. The service works from an allowed client without opening access to the public internet.

If it fails or rollback

Check console logs, template compatibility, storage content type, bridge, and resource limits. If a service requires unsupported privilege changes, stop and rebuild it in a VM rather than disabling protections blindly. To remove a disposable test, verify the container ID and data state, then delete only that container.

Safety and data notes

The container shares the host kernel. Do not treat root inside a container as a safe place to run arbitrary untrusted code. Protect credentials, patch both host and container, and maintain separate backups. Any host path bind-mounted into a container requires a deliberate access review.

Sources

Official Proxmox documentation checked 2026-09-29: container templates, setup, and security, storage content, VM alternative.

Next guide

Continue with guide 15 to schedule backups of guests you intend to keep.