You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker创建容器失败求助(无apt/dpkg环境)

Docker容器启动报错pivot_root .: invalid argument的排查与解决(无apt/dpkg环境)

问题重现

执行docker run hello-world时触发报错:

docker: Error response from daemon: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error jailing process inside rootfs: pivot_root .: invalid argument: unknown.

环境信息

  • 内核版本:Linux localhost 5.13.x #1 SMP Fri Apr 14 00:13:58 CST 2023 x86_64 GNU/Linux
  • 无apt/dpkg包管理工具,拥有完整root权限
  • Docker版本:20.10.22,此前运行正常
  • dockerd启动关键警告:

    WARN[2023-06-08T19:55:02.790387966+03:00] Failed to find ip6tables: exec: "ip6tables": executable file not found in $PATH
    WARN[2023-06-08T19:55:02.821529061+03:00] Could not load necessary modules for Conntrack: Running modprobe nf_conntrack failed with message: modprobe: invalid option -- 'a' BusyBox v1.31.1 (2023-04-14 03:02:50 CST) multi-call binary. Usage: modprobe [-rq] MODULE [SYMBOL=VALUE]... -r Remove MODULE -q Quiet, error: exit status 1


解决步骤

1. 修复pivot_root核心错误

该错误源于overlay2存储驱动的pivot_root机制与当前文件系统/内核环境不兼容,通过配置禁用pivot_root:

  1. 创建或编辑/etc/docker/daemon.json文件:
    {
      "storage-driver": "overlay2",
      "storage-opts": [
        "overlay2.override_kernel_check=true",
        "overlay2.no-pivot=true"
      ]
    }
    
  2. 重启dockerd:
    pkill dockerd
    dockerd &
    

2. 手动加载Conntrack模块

Docker默认调用的modprobe参数不兼容BusyBox版本,直接手动加载模块:

modprobe nf_conntrack
  • 若提示模块不存在,检查内核是否编译该模块:
    # 若存在内核配置文件
    zcat /proc/config.gz | grep NF_CONNTRACK
    # 或检查模块目录
    ls /lib/modules/$(uname -r)/ | grep nf_conntrack
    

3. 处理ip6tables缺失问题

ip6tables缺失会导致警告,可通过两种方式解决:

  • 方式一:利用BusyBox内置功能
    检查BusyBox是否包含ip6tables:
    busybox --list | grep ip6tables
    
    若存在,创建软链接:
    ln -s /bin/busybox /usr/sbin/ip6tables
    
  • 方式二:禁用IPv6
    编辑/etc/docker/daemon.json,添加IPv6禁用配置(与之前的存储配置合并):
    {
      "storage-driver": "overlay2",
      "storage-opts": [
        "overlay2.override_kernel_check=true",
        "overlay2.no-pivot=true"
      ],
      "ipv6": false,
      "fixed-cidr-v6": ""
    }
    

4. 验证修复

重启dockerd后,再次执行测试命令:

docker run hello-world

内容的提问来源于stack exchange,提问作者Ghost Ghaith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 05:35:39