Open Rajendraladkat1919 opened 4 years ago
This is going to be due to the selinux policy.
Do you have container-selinux
installed? What version?
@cpuguy83 its container-selinux-2.10-2.el7
The minimum required currently in the centos7 build is Requires: container-selinux >= 2:2.74
I'm not sure what that means for RHEL8.
I run into the same problem with container-selinux 2.94. After an upgrade to version 2.124 the problem was solved.
So feel free to close this issue.
I present the same problem but I am using debian9 and it tells me this
ERROR: for jenkins Cannot start service jenkins: OCI runtime create failed: container_linux.go:349: starting container process caused "process_linux.go:449: container init caused \"rootfs_linux.go:58: mounting \\"proc\\" to rootfs \\"/var/lib/docker/overlay2/bbf189ac6d27c62fa2cb1ba556b0c68b50a3cf34e47b704e9e11506f461c4186/merged\\" at \\"/proc\\" caused \\"permission denied\\"\"": unknown
What could it be??
I'm experiencing the same error vvivas. Were you able to identify and resolve the issue?
@sfescape I think reinstalling docker will works fine for me. This is related to SE linux security.
I ran into this issue this morning on rhel 7 and setting selinux to permissive resolved the issue. after adding the policy exception, I was ready to rock (meaning I was able to set selinux to enforce).
+1
raspberrypi:~ $ sestatus -bash: sestatus: command not found
I just got this as well with rhel8:
Warning Failed 60m (x4 over 63m) kubelet Error: failed to create containerd task: OCI runtime create failed: container_linux.go:380: starting container process caused: process_linux.go:545: container init caused: failed to set /proc/self/attr/keycreate on procfs: write /proc/self/attr/keycreate: invalid argument: unknown
cat /etc/system-release
Red Hat Enterprise Linux release 8.4 (Ootpa)
dnf list --installed | grep container-selinux
container-selinux.noarch 2:2.164.1-1.module+el8.4.0+11870+8b6f7018 @rhel-8-appstream-rhui-rpms
anyone have a version needed for rhel8?
I run into the same problem with container-selinux 2.94. After an upgrade to version 2.124 the problem was solved.
So feel free to close this issue.
I just tried to use that version in rhel8 (I had to downgrade to it):
dnf list --installed | grep container-selinux container-selinux.noarch 2:2.124.0-1.module+el8.2.0+6368+cf16aa14 @rhel-8-appstream-rhui-rpms
and I still get this issue. of course, the newer version above (2.164) is also getting it.
Expected behavior
It should run any docker image
Actual behavior
[root@localhost yum.repos.d]# docker run -i -t centos:7 docker: Error response from daemon: OCI runtime create failed: container_linux.go:349: starting container process caused "process_linux.go:449: container init caused \"write /proc/self/attr/keycreate: permission denied\"": unknown. ERRO[0002] error waiting for container: context canceled [root@localhost yum.repos.d]# docker run -itd busybox 5c74da43514170bb8b9d7e1c772247e81916a23cd156658d32f16446f13412e1 docker: Error response from daemon: OCI runtime create failed: container_linux.go:349: starting container process caused "process_linux.go:449: container init caused \"write /proc/self/attr/keycreate: permission denied\"": unknown. [root@localhost yum.repos.d]# docker ps
Steps to reproduce the behavior
Output of
docker version
:Output of
docker info
:Additional environment details (AWS, VirtualBox, physical, etc.) Physical RHEL 8