lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner ipc_lock sys_chroot
-lxc.mount.auto = cgroup:ro sys:ro proc
+lxc.mount.auto = cgroup:ro sys:ro
+lxc.mount.entry = proc proc proc nodev,nosuid,noexec,hidepid=2 0 0
lxc.console.path = none
lxc.pty.max = 10