Skip to content

Check for container privileged mode ...... no! Please run container with --privileged option #24

@fpuleio

Description

@fpuleio

i cannot start the vMX in privileged mode
the docker-compose file seems correct

`ciscobgp@ciscobgp-virtual-machine:~/projects/Jnp_vMX/OpenJNPR-Container-vMX$ cat docker-compose.yml
version: "3"

services:

  vmx1:
    image: juniper/openjnpr-container-vmx:bionic
    privileged: true
    tty: true`

it fails on system check

`cat src/system_check.sh
...
echo -n "Check for container privileged mode ...... "
echo "hello" 2>/dev/null > /sys/fs/cgroup/aaa
if [ $? -eq 0 ]; then
  echo yes
else
  echo "no! Please run container with --privileged option"
  fatal=$(($fatal + 1))
fi`

`ciscobgp@ciscobgp-virtual-machine:~/projects/Jnp_vMX/OpenJNPR-Container-vMX$ docker ps -a
CONTAINER ID   IMAGE                                   COMMAND                  CREATED          STATUS                      PORTS     NAMES
d17c42137504   juniper/openjnpr-container-vmx:bionic   "/launch.sh"             22 minutes ago   Exited (1) 22 minutes ago             openjnpr-container-vmx_vmx1_1`

`ciscobgp@ciscobgp-virtual-machine:~/projects/Jnp_vMX/OpenJNPR-Container-vMX$ docker logs d17c42137504
Juniper Networks vMX Docker Light Container
 
Linux d17c42137504 5.19.0-46-generic #47~22.04.1-Ubuntu SMP PREEMPT_DYNAMIC Wed Jun 21 15:35:31 UTC 2 x86_64
 
CPU Model ................................ Intel(R) Xeon(R) Gold 6240 CPU @ 2.60GHz
CPU affinity of this container ........... 0-7
KVM hardware virtualization extension .... yes
Total System Memory ...................... 31 GB
Free Hugepages ........................... yes (9 x 1024 MB = 9216 MB)
Check for container privileged mode ...... no! Please run container with --privileged option
Check for sudo/root privileges ........... yes
Loop mount filesystem capability ......... yes
docker access ............................ CONTAINER ID   IMAGE                                   COMMAND        CREATED         STATUS                  PORTS                                                                                NAMES
d17c42137504   juniper/openjnpr-container-vmx:bionic   "/launch.sh"   2 seconds ago   Up Less than a second   0.0.0.0:49154->22/tcp, :::49154->22/tcp, 0.0.0.0:49153->830/tcp, :::49153->830/tcp   openjnpr-container-vmx_vmx1_1
yes

lcpu affinity ............................  0-7

NUMA node(s):        1
NUMA node0 CPU(s):   0-7

1 failed system dependencies. Terminating`
'''

i am running docker version 20.10.21 , and i cannot find a way to make it work

ciscobgp@ciscobgp-virtual-machine:~/projects/Jnp_vMX/OpenJNPR-Container-vMX$ docker version
Client:
 Version:           20.10.21
 API version:       1.41
 Go version:        go1.18.1
 Git commit:        20.10.21-0ubuntu1~22.04.3
 Built:             Thu Apr 27 05:57:17 2023
 OS/Arch:           linux/amd64
 Context:           default
 Experimental:      true




Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions