*** sameo has joined #kata-general | 00:16 | |
*** sameo has quit IRC | 00:43 | |
kata-irc-bot1 | <archana.m.shinde> zer0def This should fix the error you see with --net=none https://github.com/kata-containers/runtime/pull/2320 | 01:19 |
---|---|---|
kata-irc-bot1 | <archana.m.shinde> Let me know if that works out for you as well | 01:19 |
kata-irc-bot1 | <archana.m.shinde> I was not able to reproduce your error with networking though, and the logs dont help much | 01:20 |
kata-irc-bot1 | <cmichel> Has anyone set up Kata containers with Core OS? | 01:23 |
kata-irc-bot1 | <eric.ernst> we should be *relatively* distro-agnostic | 01:51 |
kata-irc-bot1 | <eric.ernst> (ie, we have a set of static tarballs we also produce, and provide for deployment on k8s) | 01:51 |
*** sameo has joined #kata-general | 02:17 | |
*** igordc has quit IRC | 02:54 | |
kata-irc-bot1 | <manchenchen> Thanks .I test another function ,enable_swap = true 。When i change it to true and restart docker ,I run one docker and exec into it ,find still no swap show when free -h .Any advise on it | 02:58 |
kata-irc-bot1 | <manchenchen> And is there any way to reset the shm-size when docker(kata-runtime) run 。 | 03:05 |
*** sameo has quit IRC | 03:48 | |
zer0def | @archana.m.shinde it works, though i'm not sure whether implementing netns configuration on the runtime's end instead of letting the CRI (in this case, podman) do it is a good approach (sans the issue with 0711 on /var/run/netns) | 07:53 |
zer0def | but since i'm not exactly contributing myself, i'm in no position to complain | 07:53 |
kata-irc-bot1 | <manchenchen> When i try to use docker network connect to add one more interface ,like eth1 ,I find it works under runc ,not work under kata .It should because kata is vm,different .any advise to add one more interface in the kata vm .thanks | 08:22 |
*** sgarzare has joined #kata-general | 08:29 | |
*** gwhaley has joined #kata-general | 08:59 | |
*** lpetrut has joined #kata-general | 09:04 | |
kata-irc-bot1 | <manchenchen> Has anyone see this and advise it | 09:13 |
kata-irc-bot1 | <graham.whaley> @manchenchen - I wonder if `docker network connect` suffers from the same kata Limitation that `docker --net=xxx` does - documented at https://github.com/kata-containers/documentation/blob/master/Limitations.md#support-for-joining-an-existing-vm-network I suspect so, as `docker network connect` is trying to connect to a docker network namespace (not a physical network controller) I think? /cc @archana.m.shinde for | 09:20 |
kata-irc-bot1 | clarification. | 09:20 |
kata-irc-bot1 | <manchenchen> @graham.whaley yes,read the limitation ,docker network connect can't work .i notice that kata-runtime kata-network add-iface command maybe add one more iface into the kata vm ,but i can not find any sample in the documents。 | 09:23 |
*** sameo has joined #kata-general | 09:29 | |
*** lpetrut has quit IRC | 09:54 | |
*** sgarzare has quit IRC | 09:54 | |
*** mugsie has quit IRC | 09:54 | |
*** rha has quit IRC | 09:54 | |
*** Wimpress has quit IRC | 09:54 | |
*** sameo has quit IRC | 09:54 | |
*** gwhaley has quit IRC | 09:54 | |
*** kata-irc-bot1 has quit IRC | 09:54 | |
*** peluse has quit IRC | 09:54 | |
*** serverascode has quit IRC | 09:54 | |
*** stackedsax has quit IRC | 09:54 | |
*** manny has quit IRC | 09:54 | |
*** irclogbot_0 has quit IRC | 09:55 | |
*** trom has quit IRC | 09:55 | |
*** zer0def has quit IRC | 09:55 | |
*** sjas has quit IRC | 09:55 | |
*** EricAdamsZNC has quit IRC | 09:55 | |
*** tobberydberg has quit IRC | 09:55 | |
*** tmhoang has quit IRC | 09:55 | |
*** ChanServ has quit IRC | 09:55 | |
*** lpetrut has joined #kata-general | 10:04 | |
*** rha has joined #kata-general | 10:04 | |
*** mugsie has joined #kata-general | 10:04 | |
*** sgarzare has joined #kata-general | 10:04 | |
*** Wimpress has joined #kata-general | 10:04 | |
*** manny has joined #kata-general | 10:04 | |
*** zer0def has joined #kata-general | 10:04 | |
*** irclogbot_0 has joined #kata-general | 10:04 | |
*** tmhoang has joined #kata-general | 10:04 | |
*** trom has joined #kata-general | 10:04 | |
*** sjas has joined #kata-general | 10:04 | |
*** EricAdamsZNC has joined #kata-general | 10:04 | |
*** tobberydberg has joined #kata-general | 10:04 | |
*** ChanServ has joined #kata-general | 10:04 | |
*** orwell.freenode.net sets mode: +o ChanServ | 10:04 | |
*** sameo has joined #kata-general | 10:04 | |
*** gwhaley has joined #kata-general | 10:04 | |
*** peluse has joined #kata-general | 10:04 | |
*** kata-irc-bot1 has joined #kata-general | 10:04 | |
*** serverascode has joined #kata-general | 10:04 | |
*** stackedsax has joined #kata-general | 10:04 | |
*** kata-irc-bot has joined #kata-general | 10:05 | |
*** kata-irc-bot1 has quit IRC | 10:05 | |
*** sgarzare has quit IRC | 10:31 | |
kata-irc-bot | <graham.whaley> @manchenchen - I think `kata-network add-iface` is a kata specific runtime command, and not something that would normally get driven by the higher level orchestrators directly. iiuc, it is used to add a physical network interface into a kata container - not add a virtual network namespace like 'docker network connect' would be doing. still need to wait for @archana.m.shinde to elaborate :slightly_smiling_face: - see | 10:44 |
kata-irc-bot | https://github.com/kata-containers/runtime/issues/1876 for 'add-iface' details I think | 10:45 |
*** sgarzare has joined #kata-general | 11:18 | |
*** sameo has quit IRC | 11:19 | |
*** gwhaley has quit IRC | 12:30 | |
*** gwhaley has joined #kata-general | 13:48 | |
*** sgarzare has quit IRC | 14:06 | |
*** sgarzare has joined #kata-general | 14:12 | |
kata-irc-bot | <eric.ernst> You can do a network add via docker in a runc container, and then steal all the network interfaces from it via a new kata container that uses the original containers network. I have a gist in this somewhere.... | 15:07 |
kata-irc-bot | <eric.ernst> https://gist.github.com/egernst/0c8acf60d5aa4b6ab9d36517580c760a#launching-clear-container-with-two-vhost-user-interfaces | 15:09 |
kata-irc-bot | <eric.ernst> This is very old, but a hack I used on docker cli | 15:09 |
kata-irc-bot | <eric.ernst> Multi interfaces, using something like multus CNI in k8s works fine for kata. | 15:09 |
kata-irc-bot | <eric.ernst> @manchenchen ^^ | 15:10 |
*** igordc has joined #kata-general | 16:27 | |
*** lpetrut has quit IRC | 17:40 | |
*** sgarzare has quit IRC | 18:06 | |
*** lpetrut has joined #kata-general | 18:07 | |
*** gwhaley has quit IRC | 18:07 | |
kata-irc-bot | <archana.m.shinde> zer0def If the namespace path is empty it is the reponsibility of the OCI runtime to create the namespace | 18:23 |
kata-irc-bot | <archana.m.shinde> See this https://github.com/kata-containers/runtime/pull/2320 | 18:23 |
zer0def | uh, i think you meant to link something else? not the PR? | 18:26 |
kata-irc-bot | <archana.m.shinde> zer0def, yes I sent you the correct link | 18:29 |
kata-irc-bot | <archana.m.shinde> later | 18:29 |
kata-irc-bot | <archana.m.shinde> here : https://github.com/opencontainers/runtime-spec/blob/7c4c8f63a63693f75cfa0f3f397151fb8d9732ad/config-linux.md | 18:29 |
zer0def | ah, alright, thank you | 18:29 |
kata-irc-bot | <archana.m.shinde> runc does the same, but runc does not need a bind-mount for the network namespace, so you dont see the issue | 18:30 |
zer0def | that clarifies things… i'm a little surprised podman's doing that on their end then. again, thanks for the clarification | 18:32 |
kata-irc-bot | <archana.m.shinde> @manchenchen docker connect should work, but you need an additional deamon for monitoring changes in the network namespace | 18:34 |
kata-irc-bot | <archana.m.shinde> the daemon can be enabled with `enable_netmon=true` in the kata configuration.toml file | 18:35 |
kata-irc-bot | <archana.m.shinde> https://github.com/kata-containers/runtime/blob/master/cli/config/configuration-qemu.toml.in#L363 | 18:35 |
*** sameo has joined #kata-general | 18:35 | |
kata-irc-bot | <archana.m.shinde> We have an existing test that verifies the network connect works when the netmon daemon is enabled | 18:36 |
kata-irc-bot | <archana.m.shinde> https://github.com/kata-containers/tests/blob/dc5d9d7a5f93c8d994774491cb796f1a1980871b/integration/netmon/netmon_test.bats#L16 | 18:36 |
*** sameo has quit IRC | 19:23 | |
*** igordc has quit IRC | 20:05 | |
*** auk has joined #kata-general | 20:46 | |
*** sameo has joined #kata-general | 23:03 | |
*** sameo has quit IRC | 23:47 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!