Closed dirien closed 3 years ago
Link exising issue to this https://github.com/kubevirt/kubevirt/issues/5298
So is using Flarcar not possible for kubevirt? Do i need to ask my kubernetes provider to change something?
It is interesting that that we can't change this file:
panic: error relabeling required files: error relabeling file /dev/net/tun with label system_u:object_r:container_file_t:s0. Reason: exit status 1
This line
{"component":"virt-handler","level":"warning","msg":"Permissive mode, ignoring 'semodule' failure: out: \"libsemanage.semanage_create_store: Could not access module store at /var/lib/selinux/mcs, or it is not a directory. (Read-only file system).\\nlibsemanage.semanage_direct_connect: could not establish direct connection (Read-only file system).\\n/sbin/semodule: Could not connect to policy handler\\n\", error: exit status 1","pos":"labels.go:102","timestamp":"2021-05-28T19:31:02.168777Z"}
indicates that selinux may be set up in a non-standard way. Can you influence that somehow on STACKIT?
@rmohr, we use a standart non customise Flatcar image. I just verified it, starting Flatcar in Openstack and spawn RKE on it.
Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale
.
Stale issues rot after an additional 30d of inactivity and eventually close.
If this issue is safe to close now please do so with /close
.
/lifecycle stale
I close this isse, i can't solve it on my own. :(
I close this isse, i can't solve it on my own. :(
Sorry I missed your response.
We try to install a selinux policy by default. The issue is probably that the directories are read-only on the filesystem to avoid that someone can tamper with selinux. We would have to change our permissive mode to still continue if we can't install the policies.
Looks like this may make selinux writeable on the nodes: https://kinvolk.io/docs/flatcar-container-linux/latest/setup/security/selinux/#check-a-containers-compatibility-with-selinux-policy
@dirien the daily developer build contains #6377 now. If you are still interested you can give it a try: https://kubevirt.io/user-guide/operations/installation/#installing-the-daily-developer-builds.
Is this a BUG REPORT or FEATURE REQUEST?:
What happened:
Followed the install instructions under https://kubevirt.io/quickstart_cloud/ on a STACKIT SKE 1.19 Kubernetes.
Every other pod is running fine, except the virt handler
It panics with following error:
What you expected to happen: That everything is up and running:
By default KubeVirt will deploy 7 pods, 3 services, 1 daemonset, 3 deployment apps, 3 replica sets.
How to reproduce it (as minimally and precisely as possible):
Anything else we need to know?:
Environment:
virtctl version
): v0.41.0kubectl version
):