Error with docker inside lxc container


(Manuel) #1

Hello folks!

I’m facing with a weird problem with my server, I’m using LXC/LXD for a while with a good results overall, but since yesterday (no updates were installed) I’m having a lot of troubles when triying to create or start a docker instance.

If I run (inside a lxc container) this
$ docker run hello-world

docker: Error response from daemon: oci runtime error: could not create session key: disk quota exceeded.

this is the current version of docker (insude LXC container)

Client:
Version: 1.12.3
API version: 1.24
Go version: go1.6.2
Git commit: 6b644ec
Built: Mon, 19 Dec 2016 09:20:48 +1300
OS/Arch: linux/amd64

Server:
Version: 1.12.3
API version: 1.24
Go version: go1.6.2
Git commit: 6b644ec
Built: Mon, 19 Dec 2016 09:20:48 +1300
OS/Arch: linux/amd64

this is the version of LXC

root@xxxx:~# lxc version

2.0.9

I’ve checked almost everything (like free space, inodes, etc and everything looks fine) I have ext4 as filesystem (so no disk quota at all)

$ df -i

Filesystem Inodes IUsed IFree IUse% Mounted on
udev 8229243 499 8228744 1% /dev
tmpfs 8234072 1970 8232102 1% /run
/dev/md1 27992064 6655709 21336355 24% /
tmpfs 8234072 1 8234071 1% /dev/shm
tmpfs 8234072 4 8234068 1% /run/lock
tmpfs 8234072 16 8234056 1% /sys/fs/cgroup
/dev/md2 1281120 13 1281107 1% /home
tmpfs 8234072 4 8234068 1% /run/user/0

Any thoughts?

Outside LXC container docker works as expected (tested using hello-world docker)

If you need further information please let me know.

Thank you.


(Stéphane Graber) #2

Kinda sounds like Docker may be attempting to use the kernel keyring?
That'd certainly be a new behavior from them...

Unfortunately you version of LXD doesn't support syscall blacklisting so it's not particularly easy to test/workaround in your case...

Where did you get that version of Docker?


(Manuel) #3

Hello!

That docker version is from docker.io repo

I've found the solution; increasing /proc/sys/kernel/keys/maxkeys from 200 to a higher value (50000) fixed the problem, I think that it was because I have almost 30 lxc containers running and all of them are unprivileged.

Many thanks for your help!


(Stéphane Graber) #4

Ah, that's good to know.