Comments (8)
Had the same problem and after some debugging I could fix it for me by building the netfilter comment match module on the host system.
Activating the following kernel option and compile the module
CONFIG_NETFILTER_XT_MATCH_COMMENT=m
So my problem was the -m comment
. Hopefully it can help someone in the future
from concourse-docker.
@avoidik Gentoo and kernel version 5.4.38-gentoo
from concourse-docker.
it has failed on
{
"timestamp": "1541758414.146682024",
"source": "guardian",
"message": "guardian.iptables-runner.command.failed",
"log_level": 2,
"data": {
"argv": [
"/worker-state/4.2.1/assets/iptables/sbin/iptables",
"--wait",
"--table",
"nat",
"-A",
"w--prerouting",
"--jump",
"w--instance-pbd2incpuj9",
"-m",
"comment",
"--comment",
"cdc24ff9-ad25-4fc8-6443-5c5ae9317b35"
],
"error": "exit status 1",
"exit-status": 1,
"session": "1.2",
"stderr": "iptables: No chain/target/match by that name.\n",
"stdout": "",
"took": "2.687238ms"
}
}
from concourse-docker.
solved with docker downgrade
from concourse-docker.
It's not really a fix though. I have the same issue, and I don't plan on downgrading my Docker install.
from concourse-docker.
I agree, given the CVE-2019-5736 downgrade is not an option
from concourse-docker.
@NewJorg what OS, kernel version it was?
from concourse-docker.
I had this issue with Concourse on Kubernetes installed with Helm chart. I was using Arch on the host with kernel 5.4.94-1-lts.
After some experimenting I found that changing worker runtime to containerd
solves the issue. Here's excerpt from values.yaml I used:
concourse:
worker:
runtime: containerd
from concourse-docker.
Related Issues (20)
- Help setting up AWS Secrets manager HOT 1
- Set various env vars for keys only for the appropriate command (`web` or `worker`)
- Put ./keys/generate into the docker image
- Concourse 6.1.0 Workes Fail with net.ipv4.tcp_keepalive_time HOT 4
- Concourse 6.1.0 worker fails with private key not provided HOT 1
- Web not connecting to Db on Fedora 32 HOT 1
- Generate keys script fails on MINGW64 env
- Could not resolve host: github.com HOT 2
- Multi-arch ARM docker build HOT 7
- [7.2.0] Error starting worker - btrfs command HOT 1
- Docker Quickstart results in endless worker connection refused messages HOT 2
- fatal: repository '/tmp/git-resource-repo-cache' does not exist HOT 1
- Worker fails to start on newer version of docker HOT 3
- Worker fails: failed to retrieve kernel parameter "net.ipv4.tcp_retries1" HOT 1
- containerized concourse 7.4.1 with cgroup v2 + containerd results in "max containers reached" errors HOT 4
- How to connect the worker to the web instance? HOT 2
- using a registry-image in a task fails in concourse 7.6.0 HOT 3
- CONCOURSE_RUNTIME=containerd is not the same as --runtime containerd
- Failed to create btrfs filesystem on Kind cluster. HOT 1
- exit status 2: iptables v1.8.7 (nf_tables): Couldn't load match `conntrack'
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from concourse-docker.