Docker in LXC on Proxmox: Risks, Tradeoffs, and Lessons
In Proxmox-powered homelabs, one question comes up like clockwork: should you run Docker inside an LXC container, or play it safe and drop Docker into a virtual machine instead? It seems simple, since LXCs are lighter, faster and more resource-efficient. Under that lean surface, though, a few lurking risks have users second-guessing themselves.
From blown-up hosts to kernel panics, the debate is rooted in experience more than theory. Dozens of homelabbers have shared what works, what fails, and what they wish they knew before betting their uptime on containers inside containers. Here is the community's take on whether running Docker in an LXC is brilliant, dangerous, or both.
The appeal: speed, simplicity, and efficiency
If there's one thing Proxmox users agree on, it's that LXCs are nimble. They boot quickly, use fewer resources than a VM, and let you fine-tune resource allocation with surgical precision, which makes them attractive for running Docker.
"I use multiple LXCs. Management is just easier for me. I know this one LXC will do one thing and that's it," said one user, summing up the 'one-container-per-service' mindset.
Others run Docker inside a single LXC to keep services grouped together, especially when they're low-impact. For many it's familiar as well as efficient: if you already know Docker and compose files, throwing it in an LXC feels natural.
A few users went further still: "I've got 50 LXCs and 1 Docker VM. It's not that hard to manage if you automate the normal things." Talk about scale.
The pain points: when Docker inside LXC bites back
This is where things get messy. One user shared a cautionary tale: "A process inside my Docker LXC caused a kernel panic and it brought down my entire host. If it was a VM instead, it would have just crashed the VM." That's the nightmare scenario, and it wasn't a one-off fluke.
LXC shares the Proxmox host's kernel, so if something inside the container goes sideways, it might take the whole system with it. Some users discovered this the hard way.
"You're combining two sets of security concerns," another explained. "LXC has holes. Docker has holes. Together, you've got extra attack vectors."
Others found Docker-in-LXC simply didn't play nice with certain containers: "Not every Docker container works in LXC. My mail server didn't run properly, probably due to apparmor or something."
Mounting NFS shares or passing through hardware like GPUs brings more headaches. Docker in a VM makes that easy, while Docker in an LXC can turn into a config nightmare.
Privileged vs. unprivileged: choose your fighter
A lot of the risk comes down to whether you run your LXC as privileged or unprivileged.
Privileged LXCs act more like the host system and allow more direct access to hardware, which makes Docker happier, especially with GPU passthrough or mounting USB devices. That also makes them more dangerous, because something that goes rogue could break through and mess with your Proxmox host.
Unprivileged LXCs are safer. They sandbox things more tightly, but Docker doesn't always run smoothly in them.
One user tried the unprivileged route with rootless Podman as an alternative: "Was your LXC privileged? I went with an unprivileged LXC and rootless Podman. I don't see how that could happen in this config." Even that isn't bulletproof.
Another pointed out, "Not all things can run in unprivileged mode. Depends what you need your Docker to do."
The middle ground: hybrid approaches are gaining ground
More and more Proxmox users land somewhere in between, using VMs for core or complex Docker stacks and sticking with LXCs for lighter, less critical services.
One homelabber summarized it well: "I use LXC for my most important services, and I have a Docker VM for docker services that I don't care too much if they go down. Zero Docker on the LXCs."
Another went the opposite way, running Docker in LXCs for minor services and keeping VMs for big apps like Frigate and Immich that needed GPU access or better isolation.
A third shared: "I have one Docker-specific LXC that runs all my minor services. I've never had an issue running Docker in an LXC."
The answer clearly isn't black and white. It depends on what matters most to you, whether that's isolation, portability or simplicity.
The case for VMs: stability, security, and peace of mind
Plenty of users, especially those who've hit weird bugs or crashed their Proxmox node, now swear by putting Docker in a VM instead.
"As I understand it, LXC has some security holes and Docker has some security holes. Add them together and you get more trouble," one user wrote.
Even Proxmox's own documentation suggests, without making a fuss about it, that Docker should run in a full VM for better isolation. And when updates roll out to Proxmox, your containers inside a Docker VM keep humming. Try that with LXC and things might get spicy.
Then there's the backup issue. "LXCs don't support dirty bitmaps for backups," one user warned. "That means every time your backup runs, the whole storage gets scanned. VMs are way more efficient."
Real-world setups: what users actually do
User A runs a VM with Docker and GPU passthrough for AI workloads, which keeps things modular. User B has 11 LXCs, one per service, on a low power server and is careful about resource use. User C keeps one LXC with all Docker-only services and says it's easier than converting each app to an LXC-native install.
User D runs Docker in LXCs for "non-critical" services and accepts the occasional hiccup as the price of lightweight hosting. User E went full Kubernetes across VMs, ditching both LXC and Docker-in-LXC for something more scalable and modern.
Every setup reflects personal preference, server specs, and how much pain you're willing to tolerate when things go sideways.
Final word: more Jenga than time bomb
So is Docker in an LXC a ticking time bomb? It's more like playing Jenga. You can build something tall, efficient and beautiful, but if you pull the wrong block (update the wrong kernel, run the wrong container, misconfigure something), it can all come down harder than expected.
If your setup is just for internal services and you're comfortable tinkering, Docker in LXC can absolutely work. Go in knowing the risks and plan for recovery; snapshots, off-host backups and security hardening are your friends.
If you're running services that matter, such as anything exposed to the internet or involving authentication, media access, AI models or public APIs, maybe put them in a VM. The overhead is worth the peace of mind.
And remember that this is your homelab. You don't have to get it perfect from the start, so experiment, fail fast, and rebuild smarter.