You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RHEL 8.8上Podman 4.4.1容器无法访问但服务正常求助

问题背景

在RHEL 8.8系统中使用Podman 4.4.1以受限用户elk(rootless模式)部署ELK栈,包含三个容器:

  • k8s-elastic:Elasticsearch
  • k8s-kibana:Kibana
  • k8s-logstash:Logstash

初始运行稳定,但一段时间后Podman无法管理容器:

  • 执行podman exec -it k8s-elastic bash返回:

    Error: OCI runtime error: runc: exec failed: container does not exist

  • 执行podman stop k8s-elastic返回:

    ERRO[0000] container does not exits.

但容器内的ELK集群服务仍正常运行,且所有容器均受此影响。

排查步骤

1. 确认容器进程状态

先验证容器内服务进程是否存活:

# 检查Elasticsearch进程
ps aux | grep elasticsearch
# 检查Kibana/Logstash进程
ps aux | grep kibana
ps aux | grep logstash

若能看到对应进程,说明容器进程未终止,仅Podman丢失了容器元数据。

2. 检查Podman运行时目录

从podman info可知,rootless Podman的runRoot为/tmp/podman-run-1001/containers,而系统默认会定期清理/tmp目录下的临时文件(通过systemd-tmpfiles或tmpwatch),这会导致Podman存储的容器元数据被删除,进而无法识别容器。

检查runRoot目录及元数据:

ls -ld /tmp/podman-run-1001/containers
ls /tmp/podman-run-1001/containers/overlay-containers/

若目录为空或不存在,即可确认是临时目录清理导致的问题。

3. 验证tmp目录清理规则

查看系统临时文件清理配置:

# 检查systemd-tmpfiles规则
grep -r "/tmp" /etc/tmpfiles.d/
# 检查tmpwatch配置(若存在)
cat /etc/cron.daily/tmpwatch

确认是否有规则清理/tmp/podman-run-*类目录。

修复方案

1. 修改Podman runRoot到非临时目录

编辑用户elk的Podman存储配置文件/home/elk/.config/containers/storage.conf,找到[storage]段,将runRoot修改为非/tmp路径:

[storage]
runRoot = "/home/elk/.local/share/containers/runroot"

保存后重启所有容器(或系统),确保Podman使用新运行时目录。

2. 排除Podman临时目录的清理规则

若不想修改runRoot,可添加规则阻止系统清理Podman临时目录:
创建/etc/tmpfiles.d/podman.conf文件,内容如下:

# 保留Podman rootless运行时目录,禁止清理
d /tmp/podman-run-* 0700 elk elk -

执行以下命令生效:

systemd-tmpfiles --create /etc/tmpfiles.d/podman.conf

3. 重新生成systemd服务文件

原自动生成的systemd服务中,PIDFile指向/tmp路径,修改runRoot后需重新生成服务文件:

# 停止当前服务
systemctl --user stop container-<container-id>.service
# 重新生成服务文件
podman generate systemd --new --name k8s-elastic > ~/.config/systemd/user/container-k8s-elastic.service
# 重载服务并启动
systemctl --user daemon-reload
systemctl --user enable --now container-k8s-elastic.service

对k8s-kibana和k8s-logstash执行相同操作。

4. 升级Podman版本

Podman 4.4.1存在部分rootless模式下的已知问题,建议升级至最新稳定版(如4.9.x及以上),可通过RHEL AppStream仓库更新:

sudo dnf update podman
其他排查方向
  • SELinux上下文检查:验证挂载目录的SELinux上下文是否正确:
    ls -Z /opt/k8s-elk/elastic-data/
    
    确保上下文为system_u:object_r:container_file_t:s0。
  • Podman套接字状态:检查Podman守护进程套接字是否正常:
    ls -l /run/user/1001/podman/podman.sock
    
    若套接字丢失,重启Podman守护进程:
    systemctl --user restart podman
    

内容的提问来源于stack exchange,提问作者stsm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 00:45:56