Open vernhart opened 4 months ago
One workaround to this (instead of using net.core.devconf_inherit_init_net = 1
on the host) is to use these instance (or profile) settings:
lxc config set c1 \
linux.sysctl.net.ipv6.conf.all.accept_redirects=0 \
linux.sysctl.net.ipv6.conf.default.accept_redirects=0
lxc restart c1
lxc exec c1 -- sysctl -a | grep accept_redirect | grep all
net.ipv4.conf.all.accept_redirects = 0
net.ipv6.conf.all.accept_redirects = 0
lxc exec c1 -- sysctl -a | grep accept_redirect | grep default
net.ipv4.conf.default.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
Based on https://discourse.ubuntu.com/t/cannot-turn-off-net-ipv4-conf-rp-filter-no-matter-whats-in-etc-sysctl-conf/43611/10?u=tomp we should also confirm this isn't specific to systemd based instance OSes.
Required information
Issue description
Some sysctl network parameters are not getting set despite what is set in /etc/sysctl.conf. On both the host and container I have:
I have rebooted the host and later I rebooted the container. The results are always the same. On the host:
And in the container:
After some testing, I was able to get the desired result (all zeros) by setting
net.core.devconf_inherit_init_net = 1
in the host OS and rebooting the container.