Technical

Proxmox with arr stack in LXC: a working setup with TrueNAS mounts

Proxmox with arr stack in LXC: a working setup with TrueNAS mounts

Proxmox with arr stack in LXC is doable, but the permissions will drive you nuts if you skip the UID/GID mapping. Here’s the full setup that actually works, including TrueNAS mounts.

High-angle view of a yellow ethernet cable on a bright blue background.

The containers

I run each *arr app in its own unprivileged LXC container. Radarr, Sonarr, Lidarr, Prowlarr, qBittorrent, and Jellyfin. You can cram them all into one container, but then one bad update takes down everything. Separate containers are cleaner.

Mounting TrueNAS storage

Don’t bother with NFS inside the container. Use a bind mount from the Proxmox host. First, mount the TrueNAS share on the host with NFS. Then bind mount it into the container.

On the host, edit /etc/pve/lxc/<CTID>.conf and add:

mp0: /mnt/truenas/media,mp=/media

That’s the easy part. The hard part is permissions.

Detailed close-up of ethernet cables and network connections on a router, showcasing modern technology.

UID/GID mapping

Unprivileged containers map root inside the container to UID 100000 on the host. So files owned by UID 1000 on TrueNAS show up as UID 101000 inside the container. That means no write access.

The fix is to add a mapping. In the same config file:

lxc.idmap: u 0 100000 1000
lxc.idmap: g 0 100000 1000
lxc.idmap: u 1000 1000 1
lxc.idmap: g 1000 1000 1
lxc.idmap: u 1001 101001 64535
lxc.idmap: g 1001 101001 64535

Then create the subordinate IDs on the host:

usermod --add-subuids 100000-165535 root
usermod --add-subgids 100000-165535 root

Restart the container. Now UID 1000 inside maps to UID 1000 on the host, so the *arr apps can write to the TrueNAS share. I wrote a longer post about this exact issue: Container mount point GID mapping works, but no write access.

Networking

Put all the containers on the same bridge. Give them static IPs. Then in each *arr app, set the download client to the qBittorrent container’s IP, and set the root folder to the mounted media path. Prowlarr handles the indexers.

One gotcha: if you use a firewall on the host, allow traffic between the containers. The default bridge usually allows it, but if you added rules, check them.

My take

This setup is solid once the UID mapping is done. The forum threads leave that part half-finished. Skip it and you’ll spend an evening chasing permission errors. Get it right and the whole stack just runs.

Leave a comment

Comments are reviewed before they appear. Your email is never published.