IBM / Db2

Db2 Universal Container deployment
Apache License 2.0
9 stars 34 forks source link

Failed to create cgroup /kubepods.slice/kubepods-podbf7ceb98_8988_11ea_a877_26a3687d1032.slice/crio-ce6ea4f952fce142c5b0c21a0c90de582298da0778be9c2585293072844a4e7e.scope/system.slice/db2u_root.service: Permission denied #29

Open vgovindan opened 4 years ago

vgovindan commented 4 years ago

Installing the images using helm on IBM Cloud RHOCP V3.11 and running db2u-install script. I get following error in db2u-release-1-db2u-0 pod.

systemd 219 running in system mode. (+PAM +AUDIT +SELINUX +IMA -APPARMOR +SMACK +SYSVINIT +UTMP +LIBCRYPTSETUP +GCRYPT +GNUTLS +ACL +XZ +LZ4 -SECCOMP +BLKID +ELFUTILS +KMOD +IDN) Detected virtualization other. Detected architecture x86-64.

Welcome to Db2 Universal Container!

Set hostname to . Cannot add dependency job for unit systemd-tmpfiles-clean.timer, ignoring: Unit is masked. Cannot add dependency job for unit display-manager.service, ignoring: Unit not found. [ OK ] Reached target Timers. [ OK ] Reached target Network is Online. [ OK ] Reached target Local File Systems. [ OK ] Reached target Swap. [ OK ] Reached target Paths. [ OK ] Created slice Root Slice. [ OK ] Created slice System Slice. [ OK ] Reached target Slices. [ OK ] Listening on Journal Socket. Failed to create cgroup /kubepods.slice/kubepods-podbf7ceb98_8988_11ea_a877_26a3687d1032.slice/crio-ce6ea4f952fce142c5b0c21a0c90de582298da0778be9c2585293072844a4e7e.scope/system.slice/systemd-tmpfiles-setup.service: Permission denied Starting Create Volatile Files and Directories... [ OK ] Listening on Delayed Shutdown Socket. Failed to create cgroup /kubepods.slice/kubepods-podbf7ceb98_8988_11ea_a877_26a3687d1032.slice/crio-ce6ea4f952fce142c5b0c21a0c90de582298da0778be9c2585293072844a4e7e.scope/system.slice/run-secrets.mount: Permission denied Failed to realize cgroups for queued unit run-secrets.mount: Permission denied Failed to create cgroup /kubepods.slice/kubepods-podbf7ceb98_8988_11ea_a877_26a3687d1032.slice/crio-ce6ea4f952fce142c5b0c21a0c90de582298da0778be9c2585293072844a4e7e.scope/system.slice/mnt-blumeta0-configmap-hadr.mount: Permission denied Failed to realize cgroups for queued unit mnt-blumeta0-configmap-hadr.mount: Permission denied Failed

vgovindan commented 4 years ago

It works fine by assigning 'db2u' to 'privileged' securitycontextconstraint. What additional permission is required to use 'db2u-scc' ?