CentOS系统中使用Podman --pod选项启动容器失败问题咨询
我来帮你分析下这个问题——这不是你用错了选项,而是权限配置或者Podman环境兼容性导致的问题,咱们一步步拆解:
先还原你的问题场景
操作步骤与错误信息
使用Podman 3.0.0-dev时:
[user@server ~]$ podman pod create -n hello [user@server ~]$ podman run --pod hello hello-world
触发的错误:
ERRO[0035] error starting some container dependencies
ERRO[0035] "container_linux.go:370: starting container process caused: process_linux.go:459: container init caused: rootfs_linux.go:59: mounting "sysfs" to rootfs at "/sys" caused: operation not permitted: OCI permission denied"
Error: error starting some containers: internal libpod error
更换为Podman 2.2.1后:
[user@server ~]$ podman run --pod hello hello-world
错误变成了:
ERRO[0000] error starting some container dependencies
ERRO[0000] "selinux label is specified in config, but selinux is disabled or not supported: OCI runtime error"
Error: error starting some containers: internal libpod error
你的服务器环境是:
[user@server ~]$ cat /etc/redhat-release CentOS Stream release 8
问题根源拆解
- Podman 3.0.0-dev的sysfs挂载错误:这个版本是开发预览版,本身就存在不少未修复的bug,加上如果你是用普通用户(rootless模式)运行Podman,对sysfs这类系统文件系统的挂载会有严格的权限限制,这才触发了"操作不允许"的错误。
- Podman 2.2.1的SELinux错误:Podman默认会依赖SELinux做标签隔离,当你的系统SELinux处于禁用状态时,单独启动容器可能会自动适配,但创建pod时的配置逻辑更严格,就会触发"SELinux标签配置存在但不支持"的冲突。
具体解决方案
1. 先搞定SELinux相关问题(针对2.2.1及稳定版)
首先检查当前SELinux状态:
getenforce
- 如果输出是
Disabled:- 临时解决:创建pod和容器时加上
--security-opt label=disable,跳过SELinux标签检查:podman pod create -n hello --security-opt label=disable podman run --pod hello --security-opt label=disable hello-world - 永久解决:CentOS官方推荐启用SELinux,编辑
/etc/selinux/config,把SELINUX=disabled改成SELINUX=enforcing,重启系统后执行restorecon -R /var/lib/containers修复容器存储的SELinux标签。
- 临时解决:创建pod和容器时加上
2. 处理rootless模式的权限限制
如果你是用普通用户运行Podman:
- 先检查是否开启了用户命名空间支持,执行:
要让这个配置永久生效,编辑sysctl user.max_user_namespaces=28633/etc/sysctl.d/userns.conf,添加user.max_user_namespaces=28633,然后执行sysctl -p /etc/sysctl.d/userns.conf。 - 也可以切换到root用户试试,确认是不是rootless模式的权限限制导致的:
sudo podman pod create -n hello sudo podman run --pod hello hello-world
3. 升级到稳定版Podman
3.0.0-dev是开发版,bug概率很高,建议升级到CentOS Stream 8官方支持的稳定版本:
sudo dnf update podman
升级完成后再测试pod的使用,应该能解决大部分兼容性问题。
内容的提问来源于stack exchange,提问作者Khane

