CircleCI中使用Singularity时根文件系统提取失败问题求助
问题
我创建了一个测试仓库用于测试Snakemake工作流的容器化,该工作流在本地和Slurm集群上均可正常运行,但在CircleCI中执行时持续报错,核心错误为:
FATAL: while extracting /home/circleci/project/.snakemake/singularity/4f64024d9840ccf1a4d8836c5edc6aa5.simg: root filesystem extraction failed: extract command failed: ERROR : Failed to set mount propagation: Operation not permitted
完整报错日志如下:
Building DAG of jobs... Pulling singularity image docker://*********/test-containerize:0.0.0. Using shell: /usr/bin/bash Provided cores: 1 (use --cores to define parallelism) Rules claiming more threads will be scaled down. Conda environments: ignored Job stats: job count min threads max threads -------- ------- ------------- ------------- all 1 1 1 all_TEST 1 1 1 total 2 1 1 Select jobs to execute... [Mon Dec 19 19:42:03 2022] rule all_TEST: input: test.txt output: output.txt jobid: 1 reason: Missing output files: output.txt resources: tmpdir=/tmp Activating singularity image /home/circleci/project/.snakemake/singularity/4f64024d9840ccf1a4d8836c5edc6aa5.simg INFO: Converting SIF file to temporary sandbox... FATAL: while extracting /home/circleci/project/.snakemake/singularity/4f64024d9840ccf1a4d8836c5edc6aa5.simg: root filesystem extraction failed: extract command failed: ERROR : Failed to set mount propagation: Operation not permitted : exit status 1 [Mon Dec 19 19:42:03 2022] Error in rule all_TEST: jobid: 1 input: test.txt output: output.txt conda-env: /home/circleci/project/.snakemake/conda/cc6395ec670d10af0374c53e5653fb76_ shell: cat test.txt > output.txt (one of the commands exited with non-zero exit code; note that snakemake uses bash strict mode!) Shutting down, this might take some time. Exiting because a job execution failed. Look above for error message Complete log: .snakemake/log/2022-12-19T194136.569293.snakemake.log Exited with code exit status 1
我推测是权限问题,但本地更复杂的工作流容器化时也出现相同错误,求解决办法。
解决方案
这个错误的核心原因是CircleCI执行环境默认没有足够权限,导致Singularity无法完成挂载传播设置。以下是几种可行的解决方法:
1. 跳过Singularity临时沙箱转换
Snakemake默认会将Singularity镜像转为临时沙箱运行,这一步需要特殊权限。可以通过添加参数直接使用SIF镜像运行:
snakemake --use-singularity --singularity-args "--no-sandbox"
2. 开启CircleCI job的特权模式
在CircleCI的config.yml中,给运行Snakemake的job开启特权模式,让Singularity获得所需权限:
jobs: run-snakemake: machine: image: ubuntu-2004:202201-02 steps: - checkout - run: command: | sudo apt-get update && sudo apt-get install -y singularity-container pip install snakemake privileged: true - run: command: snakemake --use-singularity privileged: true
注意:特权模式会赋予job更高权限,请确保你的工作流和镜像来源可信。
3. 调整Singularity容器隔离参数
尝试添加--contain或--cleanenv参数,降低容器隔离级别以规避挂载传播需求:
snakemake --use-singularity --singularity-args "--contain --cleanenv"
4. 升级Singularity版本
CircleCI默认的Singularity版本可能较旧,新版本对权限处理更友好。可以在安装步骤中指定最新稳定版:
sudo wget -O- https://raw.githubusercontent.com/sylabs/singularity/main/install.sh | sudo sh -s -- --version 3.11.4
内容的提问来源于stack exchange,提问作者Ulthran
相关产品推荐
相关产品推荐

