Fedora 28中Docker启动容器报错:OCI runtime创建失败权限拒绝求助
I’ve hit this exact issue on Fedora 28 before, and it’s almost always tied to SELinux restrictions clashing with Docker’s container initialization process. Let’s walk through how to resolve it—both for an immediate fix and a permanent solution.
Temporary Workaround (Immediate, Resets on Reboot)
If you need containers up and running right away without a system restart:
- First, switch SELinux to permissive mode temporarily:
sudo setenforce 0 - Restart the Docker daemon to apply the change:
sudo systemctl restart docker - Try launching your container again—this should bypass the SELinux block for now.
Permanent Solutions
Option 1: Disable SELinux System-Wide (Use With Caution)
Disabling SELinux removes a key security layer, so only choose this if you fully understand the tradeoffs:
- Open the SELinux configuration file:
sudo nano /etc/selinux/config - Locate the line
SELINUX=enforcingand modify it to:SELINUX=permissive - Save the file and reboot your system to apply the permanent change.
Option 2: Adjust Docker to Work With SELinux (Recommended)
Instead of disabling SELinux entirely, you can tweak Docker’s settings to play nicely with it:
- Edit or create the Docker daemon config file:
sudo nano /etc/docker/daemon.json - Add the following content to disable SELinux labeling for Docker containers (this keeps system-wide SELinux active but relaxes rules for Docker):
{ "selinux-enabled": false } - Save the file and restart Docker:
sudo systemctl restart docker
Alternatively, you can apply the SELinux bypass to individual container runs:
docker run --security-opt label=disable [your-image-name]
This only disables SELinux restrictions for that specific container.
内容的提问来源于stack exchange,提问作者littlenotes

