diff --git a/man/systemd-nspawn.xml b/man/systemd-nspawn.xml index cab5990a567..d9fb8998952 100644 --- a/man/systemd-nspawn.xml +++ b/man/systemd-nspawn.xml @@ -142,6 +142,16 @@ might be necessary to add this file to the container tree manually if the OS of the container is too old to contain this file out-of-the-box. + + Note that the kernel auditing subsystem is + currently broken when used together with + containers. We hence recommend turning it off entirely + when using systemd-nspawn by + booting with audit=0 on the kernel + command line, or by turning it off at kernel build + time. If auditing is enabled in the kernel operating + systems booted in an nspawn container might refuse + log-in attempts.