]> git.ipfire.org Git - thirdparty/systemd.git/blobdiff - man/nss-mymachines.xml
core: use the correct APIs to determine whether a dual timestamp is initialized
[thirdparty/systemd.git] / man / nss-mymachines.xml
index a3e6c75d1bf984425e8b0b870acdb0ebf05e01dc..a70119e25619732829da9d8809ba1cbfd10f6c92 100644 (file)
@@ -1,9 +1,6 @@
 <?xml version='1.0'?> <!--*-nxml-*-->
 <!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
-  "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd" [
-<!ENTITY % entities SYSTEM "custom-entities.ent" >
-%entities;
-]>
+  "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd">
 
 <!--
   This file is part of systemd.
   <refsect1>
     <title>Description</title>
 
-    <para><command>nss-mymachines</command> is a plugin for the GNU
-    Name Service Switch (NSS) functionality of the GNU C Library
-    (<command>glibc</command>) providing hostname resolution for
-    containers running locally, that are registered with
-    <citerefentry><refentrytitle>systemd-machined.service</refentrytitle><manvolnum>8</manvolnum></citerefentry>.
-    The container names are resolved to IP addresses of the specific
-    container, ordered by their scope.</para>
-
-    <para>To activate the NSS modules, <literal>mymachines</literal>
-    has to be added to the line starting with
-    <literal>hosts:</literal> in
+    <para><command>nss-mymachines</command> is a plug-in module for the GNU Name Service Switch (NSS) functionality of
+    the GNU C Library (<command>glibc</command>), providing hostname resolution for the names of containers running
+    locally that are registered with
+    <citerefentry><refentrytitle>systemd-machined.service</refentrytitle><manvolnum>8</manvolnum></citerefentry>.  The
+    container names are resolved to the IP addresses of the specific container, ordered by their scope. This
+    functionality only applies to containers using network namespacing.</para>
+
+    <para>The module also resolves user and group IDs used by containers to user and group names indicating the
+    container name, and back. This functionality only applies to containers using user namespacing.</para>
+
+    <para>To activate the NSS module, add <literal>mymachines</literal> to the lines starting with
+    <literal>hosts:</literal>, <literal>passwd:</literal> and <literal>group:</literal> in
     <filename>/etc/nsswitch.conf</filename>.</para>
 
-    <para>It is recommended to place <literal>mymachines</literal>
-    near the end of the <filename>nsswitch.conf</filename> line to
-    make sure that this mapping is only used as fallback, and any DNS
-    or <filename>/etc/hosts</filename> based mapping takes
-    precedence.</para>
+    <para>It is recommended to place <literal>mymachines</literal> after the <literal>files</literal> or
+    <literal>compat</literal> entry of the <filename>/etc/nsswitch.conf</filename> lines to make sure that its mappings
+    are preferred over other resolvers such as DNS, but so that <filename>/etc/hosts</filename>,
+    <filename>/etc/passwd</filename> and <filename>/etc/group</filename> based mappings take precedence.</para>
   </refsect1>
 
   <refsect1>
     <title>Example</title>
 
-    <para>Here's an example <filename>/etc/nsswitch.conf</filename>
-    file, that enables <command>mymachines</command> correctly:</para>
+    <para>Here is an example <filename>/etc/nsswitch.conf</filename> file that enables
+    <command>nss-mymachines</command> correctly:</para>
 
-<programlisting>passwd:   compat
-group:    compat
-shadow:   compat
+    <programlisting>passwd:         compat <command>mymachines</command> systemd
+group:          compat <command>mymachines</command> systemd
+shadow:         compat
 
-hosts:    files dns <command>mymachines</command> myhostname
+hosts:          files <command>mymachines</command> resolve myhostname
 networks:       files
 
 protocols:      db files
 services:       db files
-ethers:   db files
-rpc:      db files
+ethers:         db files
+rpc:            db files
 
 netgroup:       nis</programlisting>
 
@@ -106,6 +103,8 @@ netgroup:       nis</programlisting>
     <para>
       <citerefentry><refentrytitle>systemd</refentrytitle><manvolnum>1</manvolnum></citerefentry>,
       <citerefentry><refentrytitle>systemd-machined.service</refentrytitle><manvolnum>8</manvolnum></citerefentry>,
+      <citerefentry><refentrytitle>nss-systemd</refentrytitle><manvolnum>8</manvolnum></citerefentry>,
+      <citerefentry><refentrytitle>nss-resolve</refentrytitle><manvolnum>8</manvolnum></citerefentry>,
       <citerefentry><refentrytitle>nss-myhostname</refentrytitle><manvolnum>8</manvolnum></citerefentry>,
       <citerefentry project='man-pages'><refentrytitle>nsswitch.conf</refentrytitle><manvolnum>5</manvolnum></citerefentry>,
       <citerefentry project='man-pages'><refentrytitle>getent</refentrytitle><manvolnum>1</manvolnum></citerefentry>