You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Concourse Worker创建容器失败:iptables报错求助

Troubleshooting "iptables: No chain/target/match by that name" When Running Concourse Worker in Docker on Gentoo

Let’s break down what’s causing this error and how to fix it—this is a common compatibility issue between Concourse’s Guardian container runtime and Gentoo’s customized kernel/iptables setup.

Root Cause

From your logs, the error triggers when Guardian tries to run an iptables command using the conntrack match module (-m conntrack). This usually fails for one of two key reasons:

  • The nf_conntrack kernel module isn’t loaded on your Gentoo host
  • The iptables binary bundled with Concourse is incompatible with your host’s newer kernel modules (Gentoo often uses more up-to-date kernel/iptables versions than what’s packaged in the default Concourse image)

Step-by-Step Fixes

1. Load the Required Kernel Module First

First, check if the nf_conntrack module is active on your host:

lsmod | grep nf_conntrack

If you get no output, load it manually:

sudo modprobe nf_conntrack

To make this setting persist across reboots (Gentoo-specific), create a module load config file:

echo "nf_conntrack" | sudo tee /etc/modules-load.d/concourse.conf

2. Use the Host’s Iptables Binary Instead of Concourse’s Bundled One

Concourse ships its own iptables binaries, which might not play nice with your Gentoo kernel. Mount your host’s iptables into the container to resolve this mismatch:
Update your docker-compose.yml to add a volume mount, and fill in a concrete subnet for CONCOURSE_GARDEN_NETWORK (leaving it empty can cause network config issues):

version: '3'
services:
  worker:
    image: private-concourse-worker-with-keys
    command: worker
    ports:
      - "7777:7777"
      - "7788:7788"
      - "7799:7799"
    privileged: true
    volumes:
      - /sbin/iptables:/worker-state/3.6.0/assets/iptables/sbin/iptables # Match the path from your logs
    environment:
      - CONCOURSE_TSA_HOST=concourse-web-1.dev
      - CONCOURSE_GARDEN_NETWORK=10.254.0.0/16

Note: Double-check the path /worker-state/3.6.0/assets/iptables/sbin/iptables matches what’s in your logs—if you’re using a different Concourse version, the version number in the path will change.

3. Verify Gentoo Kernel Configuration

Ensure your kernel has Conntrack support enabled. Check your current kernel config:

zcat /proc/config.gz | grep NF_CONNTRACK

You should see entries like:

CONFIG_NF_CONNTRACK=y
CONFIG_NF_CONNTRACK_IPV4=y

If these are set to n or missing, you’ll need to recompile your kernel with these options enabled (follow Gentoo’s standard kernel recompilation workflow: edit /usr/src/linux/.config, run make && make modules_install && make install, then reboot).

4. Update Concourse to a Newer Version

Older versions of Concourse’s Guardian runtime have known compatibility issues with newer Linux kernels. If the above steps don’t work, try updating your base image in your Dockerfile:

FROM concourse/concourse:latest # Or a specific recent version like 7.10.0
COPY keys/tsa_host_key.pub /concourse-keys/tsa_host_key.pub
COPY keys/worker_key /concourse-keys/worker_key

Final Checks

After applying these fixes, restart your worker container to test:

docker-compose down && docker-compose up -d

Monitor the logs to confirm the iptables error no longer appears.

内容的提问来源于stack exchange,提问作者smitt04

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 04:18:08