Hello again. I have some docker containers in my Incus containers. Some of them are running ok, but other aren’t. I’m receiving this message when docker compose up
Error response from daemon: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: unable to join session keyring: unable to create session key: disk quota exceeded: unknown
It is fixed using
echo 200000 | sudo tee /proc/sys/kernel/keys/maxkeys
I’ve faced this problem before. It is strange that is was working with LXD with a maxkey limit of 200!
The other problem I’m facing is happening in only one container. It is Rocky 9.4 now. The docker daemon doesn’t run, and dockerd --debug returns:
dockerd --debug
INFO[2024-08-29T15:45:55.524465674Z] Starting up
DEBU[2024-08-29T15:45:55.524958975Z] Listener created for HTTP on unix (/var/run/docker.sock)
DEBU[2024-08-29T15:45:55.540630308Z] Golang's threads limit set to 922050
DEBU[2024-08-29T15:45:55.540992017Z] metrics API listening on /var/run/docker/metrics.sock
DEBU[2024-08-29T15:45:55.546536378Z] Using default logging driver json-file
DEBU[2024-08-29T15:45:55.546632353Z] No quota support for local volumes in /var/lib/docker/volumes: Filesystem does not support, or has not enabled quotas
DEBU[2024-08-29T15:45:55.546719068Z] processing event stream module=libcontainerd namespace=plugins.moby
INFO[2024-08-29T15:45:55.557498528Z] [graphdriver] trying configured driver: fuse-overlayfs
DEBU[2024-08-29T15:45:55.557555432Z] Initialized graph driver fuse-overlayfs
DEBU[2024-08-29T15:45:55.568921836Z] Max Concurrent Downloads: 3
DEBU[2024-08-29T15:45:55.568937583Z] Max Concurrent Uploads: 5
DEBU[2024-08-29T15:45:55.568943050Z] Max Download Attempts: 5
INFO[2024-08-29T15:45:55.568955397Z] Loading containers: start.
DEBU[2024-08-29T15:45:55.569145589Z] processing event stream module=libcontainerd namespace=moby
DEBU[2024-08-29T15:45:55.570405947Z] loaded container container=ab07a9bd5e87c32b1081d15bdae564366185075850ac872644a7e98b1a304629 paused=false running=false
DEBU[2024-08-29T15:45:55.570409096Z] loaded container container=36c080f1cbabc749893086dc65a9c9b4179abd8cf2cb127ca41eef49c3b79b33 paused=false running=false
DEBU[2024-08-29T15:45:55.570488080Z] loaded container container=da2937c0041a0e3ccfbc10bed871d33134bf561e7c95069dc4634a5b175dbd54 paused=false running=false
DEBU[2024-08-29T15:45:55.593659476Z] restoring container container=da2937c0041a0e3ccfbc10bed871d33134bf561e7c95069dc4634a5b175dbd54 paused=false restarting=false running=false
DEBU[2024-08-29T15:45:55.594235335Z] done restoring container container=da2937c0041a0e3ccfbc10bed871d33134bf561e7c95069dc4634a5b175dbd54 paused=false restarting=false running=false
DEBU[2024-08-29T15:45:55.594771909Z] restoring container container=ab07a9bd5e87c32b1081d15bdae564366185075850ac872644a7e98b1a304629 paused=false restarting=false running=false
DEBU[2024-08-29T15:45:55.595084026Z] done restoring container container=ab07a9bd5e87c32b1081d15bdae564366185075850ac872644a7e98b1a304629 paused=false restarting=false running=false
DEBU[2024-08-29T15:45:55.596864311Z] restoring container container=36c080f1cbabc749893086dc65a9c9b4179abd8cf2cb127ca41eef49c3b79b33 paused=false restarting=false running=false
DEBU[2024-08-29T15:45:55.597158919Z] done restoring container container=36c080f1cbabc749893086dc65a9c9b4179abd8cf2cb127ca41eef49c3b79b33 paused=false restarting=false running=false
DEBU[2024-08-29T15:45:55.597195554Z] Option DefaultDriver: bridge
DEBU[2024-08-29T15:45:55.597208991Z] Option DefaultNetwork: bridge
DEBU[2024-08-29T15:45:55.597215125Z] Network Control Plane MTU: 1500
WARN[2024-08-29T15:45:55.598666794Z] Running modprobe bridge br_netfilter failed with message: modprobe: WARNING: Module bridge not found in directory /lib/modules/5.14.0-427.31.1.el9_4.x86_64
modprobe: WARNING: Module br_netfilter not found in directory /lib/modules/5.14.0-427.31.1.el9_4.x86_64
, error: exit status 1
INFO[2024-08-29T15:45:55.601894278Z] unable to detect if iptables supports xlock: 'iptables --wait -L -n': `modprobe: FATAL: Module ip_tables not found in directory /lib/modules/5.14.0-427.31.1.el9_4.x86_64
iptables v1.8.10 (legacy): can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.` error="exit status 3"
DEBU[2024-08-29T15:45:55.602002634Z] /usr/sbin/iptables, [-t filter -C FORWARD -j DOCKER-ISOLATION]
DEBU[2024-08-29T15:45:55.603910782Z] /usr/sbin/iptables, [-t nat -D PREROUTING -m addrtype --dst-type LOCAL -j DOCKER]
DEBU[2024-08-29T15:45:55.607944359Z] /usr/sbin/iptables, [-t nat -D OUTPUT -m addrtype --dst-type LOCAL ! --dst 127.0.0.0/8 -j DOCKER]
DEBU[2024-08-29T15:45:55.611988888Z] /usr/sbin/iptables, [-t nat -D OUTPUT -m addrtype --dst-type LOCAL -j DOCKER]
DEBU[2024-08-29T15:45:55.615973541Z] /usr/sbin/iptables, [-t nat -D PREROUTING]
DEBU[2024-08-29T15:45:55.617706497Z] /usr/sbin/iptables, [-t nat -D OUTPUT]
DEBU[2024-08-29T15:45:55.619462535Z] /usr/sbin/iptables, [-t nat -F DOCKER]
DEBU[2024-08-29T15:45:55.621272519Z] /usr/sbin/iptables, [-t nat -X DOCKER]
DEBU[2024-08-29T15:45:55.623076557Z] /usr/sbin/iptables, [-t filter -F DOCKER]
DEBU[2024-08-29T15:45:55.624820471Z] /usr/sbin/iptables, [-t filter -X DOCKER]
DEBU[2024-08-29T15:45:55.626648527Z] /usr/sbin/iptables, [-t filter -F DOCKER-ISOLATION-STAGE-1]
DEBU[2024-08-29T15:45:55.628377140Z] /usr/sbin/iptables, [-t filter -X DOCKER-ISOLATION-STAGE-1]
DEBU[2024-08-29T15:45:55.630208887Z] /usr/sbin/iptables, [-t filter -F DOCKER-ISOLATION-STAGE-2]
DEBU[2024-08-29T15:45:55.632041867Z] /usr/sbin/iptables, [-t filter -X DOCKER-ISOLATION-STAGE-2]
DEBU[2024-08-29T15:45:55.633830406Z] /usr/sbin/iptables, [-t filter -F DOCKER-ISOLATION]
DEBU[2024-08-29T15:45:55.635569401Z] /usr/sbin/iptables, [-t filter -X DOCKER-ISOLATION]
DEBU[2024-08-29T15:45:55.637321391Z] /usr/sbin/iptables, [-t nat -n -L DOCKER]
DEBU[2024-08-29T15:45:55.639065114Z] /usr/sbin/iptables, [-t nat -N DOCKER]
DEBU[2024-08-29T15:45:55.641000152Z] daemon configured with a 15 seconds minimum shutdown timeout
DEBU[2024-08-29T15:45:55.641027274Z] start clean shutdown of all containers with a 15 seconds timeout...
DEBU[2024-08-29T15:45:55.641839178Z] Cleaning up old mountid : start.
INFO[2024-08-29T15:45:55.641886122Z] stopping event stream following graceful shutdown error="<nil>" module=libcontainerd namespace=moby
DEBU[2024-08-29T15:45:55.642044012Z] Cleaning up old mountid : done.
failed to start daemon: Error initializing network controller: error obtaining controller instance: failed to register "bridge" driver: failed to create NAT chain DOCKER: iptables failed: iptables -t nat -N DOCKER: modprobe: FATAL: Module ip_tables not found in directory /lib/modules/5.14.0-427.31.1.el9_4.x86_64
iptables v1.8.10 (legacy): can't initialize iptables table `nat': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
(exit status 3)
Once again, it was working before migration … do you know what can be happening?
oh, the container config:
architecture: x86_64
config:
image.architecture: amd64
image.description: Rockylinux 9 amd64 (20240205_02:06)
image.os: Rockylinux
image.release: "9"
image.serial: "20240205_02:06"
image.type: squashfs
image.variant: default
raw.idmap: both 1000 1000
security.nesting: "true"
security.syscalls.intercept.mknod: "true"
security.syscalls.intercept.setxattr: "true"
volatile.base_image: d30a41f3c51c5bc88d3ee1497a82d8e5cd8844f836d7eeb6f51e2beecc1d78e1
volatile.cloud-init.instance-id: 419ec603-ace1-4ae4-b80f-38d3b9e8a117
volatile.eth0.host_name: vethab51f2a6
volatile.eth0.hwaddr: 00:16:3e:7a:68:e5
volatile.idmap.base: "0"
volatile.idmap.current: '[{"Isuid":true,"Isgid":false,"Hostid":1000000,"Nsid":0,"Maprange":1000},{"Isuid":true,"Isgid":true,"Hostid":1000,"Nsid":1000,"Maprange":1},{"Isuid":true,"Isgid":false,"Hostid":1001001,"Nsid":1001,"Maprange":64535},{"Isuid":false,"Isgid":true,"Hostid":1000000,"Nsid":0,"Maprange":1000},{"Isuid":false,"Isgid":true,"Hostid":1001001,"Nsid":1001,"Maprange":64535}]'
volatile.idmap.next: '[{"Isuid":true,"Isgid":false,"Hostid":1000000,"Nsid":0,"Maprange":1000},{"Isuid":true,"Isgid":true,"Hostid":1000,"Nsid":1000,"Maprange":1},{"Isuid":true,"Isgid":false,"Hostid":1001001,"Nsid":1001,"Maprange":64535},{"Isuid":false,"Isgid":true,"Hostid":1000000,"Nsid":0,"Maprange":1000},{"Isuid":false,"Isgid":true,"Hostid":1001001,"Nsid":1001,"Maprange":64535}]'
volatile.last_state.idmap: '[]'
volatile.last_state.power: RUNNING
volatile.last_state.ready: "false"
volatile.uuid: 82599408-a2cd-47d1-85ac-be975c08d47f
volatile.uuid.generation: 82599408-a2cd-47d1-85ac-be975c08d47f
devices:
eth0:
ipv4.address: 192.168.5.108
name: eth0
network: lxdbr0
type: nic
gpu:
id: "0"
type: gpu
mainconf:
path: /mnt/main/conf/u8
source: /mnt/main/conf/u8
type: disk
maindata:
path: /mnt/main/data/u8/
source: /mnt/main/data/u8/
type: disk
ephemeral: false
profiles:
- default
stateful: false
description: ""