You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Debian11上Docker构建执行RUN命令失败,runc报-keep参数未定义

问题:Docker构建时runc报错"flag provided but not defined: -keep"

环境与Dockerfile内容

在Debian 11系统上构建Python脚本的Docker镜像,使用的Dockerfile如下:

FROM python:3.12-slim

WORKDIR /usr/local/app

COPY requirements.txt ./
RUN pip install --no-cache-dir -r requirements.txt

COPY PythonScript.py ./
CMD ["python", "PythonScript.py --arg1 value1 --..."]

执行构建命令docker build -t myApp .时失败,报错关联runc的未定义flag -keep。

错误日志详情

> [4/5] RUN pip install --no-cache-dir -r requirements.txt:
#5 0.035 Incorrect Usage: flag provided but not defined: -keep
#5 0.035   
#5 0.035 NAME:
#5 0.035    runc run - create and run a container
#5 0.035 
#5 0.035 USAGE:
#5 0.035    runc run [command options] <container-id>
#5 0.035 
#5 0.035 Where "<container-id>" is your name for the instance of the container that you
#5 0.035 are starting. The name you provide for the container instance must be unique on
#5 0.035 your host.
#5 0.035 
#5 0.035 DESCRIPTION:
#5 0.035    The run command creates an instance of a container for a bundle. The bundle
#5 0.035 is a directory with a specification file named "config.json" and a root
#5 0.035 filesystem.
#5 0.035 
#5 0.035 The specification file includes an args parameter. The args parameter is used   
#5 0.035 to specify command(s) that get run when the container is started. To change    the
#5 0.035 command(s) that get executed on start, edit the args parameter of the spec. See
#5 0.035 "runc spec --help" for more explanation.
#5 0.035 
#5 0.035 OPTIONS:
#5 0.035    --bundle value, -b value  path to the root of the bundle directory, defaults to the current directory
#5 0.035    --console-socket value    path to an AF_UNIX socket which will receive a file descriptor referencing the master end of the console's pseudoterminal
#5 0.035    --detach, -d              detach from the container's process
#5 0.035    --pid-file value          specify the file to write the process id to
#5 0.035    --no-subreaper            disable the use of the subreaper used to reap reparented processes
#5 0.035    --no-pivot                do not use pivot root to jail process inside rootfs.  This should be used whenever the rootfs is on top of a ramdisk
#5 0.035    --no-new-keyring          do not create a new session keyring for the container.  This will cause the container to inherit the calling processes session key
#5 0.035    --preserve-fds value      Pass N additional file descriptors to the container (stdio + $LISTEN_FDS + N in total) (default: 0)
#5 0.035    
#5 0.036 flag provided but not defined: -keep
------
process "/bin/sh -c pip install --no-cache-dir -r requirements.txt" did not complete successfully: exit code: 1

已尝试的无效排查操作

  • 将runc更新到Debian Bullseye最新版本v1.0.0-rc93
  • 将Docker更新到最新版本27.3.1
  • 将Dockerfile中的RUN行改为单独安装命令(如pip install requests)
  • 在其他RUN命令前添加RUN pip install --no-cache-dir --upgrade pip,仍触发相同错误
  • 执行RUN ls -l也会触发相同错误

解决方案

这个错误的核心原因是Docker daemon的配置中错误地向runc传递了不支持的-keep参数,所有需要启动容器的操作(比如RUN指令)都会触发该错误。具体修复步骤如下:

  1. 检查Docker daemon配置文件
    打开/etc/docker/daemon.json,查看是否存在类似以下的错误配置:

    {
      "exec-opts": ["-keep"]
    }
    

    如果有,删除-keep参数,保存文件后重启Docker服务:

    systemctl daemon-reload
    systemctl restart docker
    
  2. 检查systemd服务配置
    如果daemon.json无问题,检查Docker的systemd服务文件/lib/systemd/system/docker.service,查看ExecStart行是否包含多余的-keep参数。例如错误的配置可能是:

    ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock -keep
    

    修改为正确的参数后,重启服务:

    systemctl daemon-reload
    systemctl restart docker
    
  3. 验证修复效果
    重新执行Docker构建命令,确认错误是否消失。

内容的提问来源于stack exchange,提问作者WolfiG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 19:04:55