如何在同一Apptainer实例中开启双Shell?启动实例遇错求助
问题:Apptainer带Overlay与Fakeroot启动实例失败
背景
需要在带Overlay的容器中开启两个Shell,计划先启动一个instance再两次进入容器。为避免影响共享服务器其他用户,使用--fakeroot构建镜像和Overlay,但执行启动命令时失败。
执行命令
apptainer instance start --fakeroot --overlay my_overlay.img my_image.sif my_new_instance_name
错误输出
INFO: User not listed in /etc/subuid, trying root-mapped namespace INFO: Using fakeroot command combined with root-mapped namespace INFO: Terminating fuse-overlayfs after timeout INFO: Timeouts can be caused by a running background process INFO: Cleanup error: while stopping driver for /var/lib/apptainer/mnt/session/final: fuse-overlayfs exited: fuse: failed to unmount /var/lib/apptainer/mnt/session/final: Invalid argument ERROR: container cleanup failed: no instance found with name my_new_instance_name FATAL: container creation failed: while applying cgroups config: unable to start unit "apptainer-2317013.scope" (properties [{Name:Description Value:"libcontainer container 2317013"} {Name:Slice Value:"system.slice"} {Name:Delegate Value:true} {Name:PIDs Value:@au [2317013]} {Name:MemoryAccounting Value:true} {Name:CPUAccounting Value:true} {Name:IOAccounting Value:true} {Name:TasksAccounting Value:true} {Name:DefaultDependencies Value:false}]): Interactive authentication required. FATAL: while executing starter: failed to start instance: while running /usr/libexec/apptainer/bin/starter: exit status 255
错误分析与解决方案
核心错误点
- 用户未在
/etc/subuid中注册:导致Fakeroot只能回退到root-mapped命名空间,增加权限冲突风险 - Fuse-Overlayfs卸载超时:Overlay挂载点无法正常卸载,可能是权限不足或后台进程占用
- Systemd Cgroup权限不足:启动cgroup单元需要交互式认证,普通用户无此权限
解决步骤
- 注册Subuid/Subgid:联系服务器管理员将你的用户名添加到
/etc/subuid和/etc/subgid文件中,让Fakeroot可以使用专属的用户命名空间,避免root-mapped模式的权限问题 - 绕过Cgroup检查:启动实例时添加
--no-cgroups参数,跳过Systemd cgroup配置,命令修改为:apptainer instance start --fakeroot --no-cgroups --overlay my_overlay.img my_image.sif my_new_instance_name - 检查Overlay镜像:确保
my_overlay.img的权限正确(当前用户有读写权限),启动前关闭所有可能占用该Overlay挂载点的进程,必要时重新创建Overlay镜像
内容的提问来源于stack exchange,提问作者Eric Auld
相关产品推荐
相关产品推荐

