Closed 7underlines closed 1 year ago
Error: unable to start container 54e78abb4cb4e6e0f877caf13635b01bc4b27b61c16b4ff35ca6a0e86e986fb6: plugin type="firewall"
@thomaspeissl , I don't think you are using this plugin.
I'm having a similar issue in a slightly different context. On a EL 8.7 machine, iptables -L
runs successfully, until this plugin is used once. Subsequent calls to iptables -L
returns iptables v1.8.4 (nf_tables): table 'filter' is incompatible, use 'nft' tool.
. So I assume these plugins are altering the default tables such that you can't read them with the legacy iptables
command anymore.
This unfortunately interferes with the CNI bridge
plugin with ipmasq: true
which reads/alters the nat
table using legacy iptables
command.
I found this issue: https://github.com/containernetworking/plugins/issues/461 which led to the creation of these nftables plugins for firewall and portmap. Did you ever solve the issue with the bridge plugin needing legacy iptables, or did you work around it somehow?
@ctrlaltdel121 Unfortunately, my only workaround that worked was switching to Docker.
I'm unable to get this working in RHEL 8.7. Is it even possible? I followed the instructions from https://github.com/greenpau/cni-plugins#getting-started (instead of
go get
I had to rungo install
) I cannot see that the cni-plugin gets loaded. The directory/usr/local/lib/cni/
didn't exist for me - so I created it as root.Containers with network always fail to start with this error:
Related: https://github.com/containers/podman/issues/5569