This is the creation and basic setup of a Linux container running Alpine linux on Proxmox. I've used this a few times. Rather than have it in every page that uses it, I'll just link back to this. This assumes the Bastion is already up and running.
Create container
pveam available --section system # List available container templates
pveam download local alpine-3.23-default_20260116_amd64.tar.xz # Download Alpine container template
pveam list local # Verify template has been downloaded
pct create 100 local:vztmpl/alpine-3.23-default_20260116_amd64.tar.xz \
--hostname [hostname] \
--memory 64 \
--cores 1 \
--rootfs local-lvm:1 \
--net0 name=eth0,bridge=vmbr0,gw=192.168.1.1,ip=[static IP]/24 \
--ostype alpine \
--unprivileged 1
pct set 100 --onboot 1
pct start 100
pct enter 100
apk update
apk upgrade
Enable automatic updates
crontab -e
Add the line:
0 2 * * * apk update && apk upgrade
Install + configure SSH server
apk add openssh
rc-service sshd start
rc-update add sshd # Set to start on reboot
Disable root login.
vi /etc/ssh/sshd_config
Change #PermitRootLogin prohibit-password
to PermitRootLogin no
Create/configure new user. From here.
setup-user -a damo # Creates a locked user
grep damo /etc/passwd
# damo:x:1000:1000::/home/damo:/bin/bash # Check if shell is bash or ash
apk add shadow
chsh -s /bin/ash damo
grep damo /etc/passwd
# damo:x:1000:1000::/home/damo:/bin/ash # Fixed!
passwd damo # Set a password and unlock user
su - damo
doas pwd
# doas: /etc/doas.d/20-wheel.conf is writable by group or other
exit
ls -l /etc/doas.d/20-wheel.conf
# -rw-rw-r-- 1 root root 22 Jul 4 13:17 /etc/doas.d/20-wheel.conf
chmod 640 /etc/doas.d/20-wheel.conf
ls -l /etc/doas.d/20-wheel.conf
# -rw-r----- 1 root root 22 Jul 4 13:17 /etc/doas.d/20-wheel.conf
su - damo
doas pwd
# doas (damo@bastion) password:
/home/damo
Configure ssh. Create key pair on dev machine ssh-keygen -t ed25519. Then
on new container:
mkdir -p /home/damo/.ssh
chmod 700 /home/damo/.ssh/
echo "ssh-ed25519 XXX damo@thinkpad" > /home/damo/.ssh/authorized_keys
chmod 600 /home/damo/.ssh/authorized_keys
Configure firewall
Install iptables and create rules to allow SSH connections from the Bastion
only.
apk add iptables
rc-update add iptables # Set to start on reboot
iptables -A INPUT -p tcp --dport 22 -s 192.168.1.14 -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j DROP
rc-service iptables save # Save rules to disk