You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器无法启动报OCI runtime create failed错误求助

Troubleshooting OCI Runtime Error in Docker 17.12.0-ce on RHEL 7.2

Hey there! Let's work through this OCI runtime error you're hitting when starting containers. Looking at your docker info output, there are a few key issues we can target first to get things working again.

1. Fix the Missing Runc Runtime Version

Your docker info shows runc version: N/A (expected: b2567b37d7b75eb4cf325b77297b140ea686ce8f) — this means the runc component (critical for running containers) is either corrupted or wasn't installed properly. Here's how to fix it:

  • Stop the Docker service first:
    systemctl stop docker
    
  • Reinstall the Docker CE package to restore the correct runc binary (match your exact version):
    yum reinstall docker-ce-17.12.0.ce-1.el7.centos.x86_64
    
  • Start Docker back up:
    systemctl start docker
    
  • Verify the fix by checking docker info again — the runc version should now show the expected hash instead of N/A.

2. Replace Devicemapper Loopback with a Better Storage Driver

The devicemapper storage driver using loopback devices (as shown in your docker info warnings) is not recommended and can cause stability/performance issues, especially for container startup. Let's switch to overlay2 (supported in RHEL 7.2 with Docker 17.12):

Warning: This step will delete all existing Docker images and containers. Backup any important data first!

  • Stop Docker:
    systemctl stop docker
    
  • Remove the existing Docker data directory:
    rm -rf /var/lib/docker
    
  • Create or edit the Docker daemon config file /etc/docker/daemon.json to set the storage driver:
    {
      "storage-driver": "overlay2"
    }
    
  • Start Docker and test with a simple container:
    systemctl start docker
    docker pull alpine
    docker run -it alpine sh
    

If overlay2 doesn't work for some reason, you can try the older overlay driver instead.

3. Check Cgroup Driver Compatibility

Your Docker is using cgroupfs as the cgroup driver, but RHEL 7 uses systemd as its init system, which works better with the systemd cgroup driver. Switching might resolve runtime conflicts:

  • Edit /etc/docker/daemon.json to add the cgroup driver setting:
    {
      "exec-opts": ["native.cgroupdriver=systemd"]
    }
    
  • Restart Docker:
    systemctl restart docker
    
  • Try starting a container again.

4. Enable Required Bridge Kernel Parameters

The warnings about bridge-nf-call-iptables and bridge-nf-call-ip6tables being disabled can cause network-related issues for containers. Let's enable them:

  • Temporary fix (resets after reboot):
    echo 1 > /proc/sys/net/bridge/bridge-nf-call-iptables
    echo 1 > /proc/sys/net/bridge/bridge-nf-call-ip6tables
    
  • Permanent fix (survives reboots):
    Edit /etc/sysctl.conf and add these lines:
    net.bridge.bridge-nf-call-iptables = 1
    net.bridge.bridge-nf-call-ip6tables = 1
    
    Then apply the changes:
    sysctl -p
    

If the Issue Persists

If none of the above steps work, check the Docker service logs for more detailed error messages:

journalctl -u docker.service

Look for lines that mention the OCI runtime error — they might give specific clues about why the container can't start.

内容的提问来源于stack exchange,提问作者vhashmode

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:07:29