Concourse Worker创建容器失败:iptables报错求助
Let’s break down what’s causing this error and how to fix it—this is a common compatibility issue between Concourse’s Guardian container runtime and Gentoo’s customized kernel/iptables setup.
Root Cause
From your logs, the error triggers when Guardian tries to run an iptables command using the conntrack match module (-m conntrack). This usually fails for one of two key reasons:
- The nf_conntrack kernel module isn’t loaded on your Gentoo host
- The iptables binary bundled with Concourse is incompatible with your host’s newer kernel modules (Gentoo often uses more up-to-date kernel/iptables versions than what’s packaged in the default Concourse image)
Step-by-Step Fixes
1. Load the Required Kernel Module First
First, check if the nf_conntrack module is active on your host:
lsmod | grep nf_conntrack
If you get no output, load it manually:
sudo modprobe nf_conntrack
To make this setting persist across reboots (Gentoo-specific), create a module load config file:
echo "nf_conntrack" | sudo tee /etc/modules-load.d/concourse.conf
2. Use the Host’s Iptables Binary Instead of Concourse’s Bundled One
Concourse ships its own iptables binaries, which might not play nice with your Gentoo kernel. Mount your host’s iptables into the container to resolve this mismatch:
Update your docker-compose.yml to add a volume mount, and fill in a concrete subnet for CONCOURSE_GARDEN_NETWORK (leaving it empty can cause network config issues):
version: '3' services: worker: image: private-concourse-worker-with-keys command: worker ports: - "7777:7777" - "7788:7788" - "7799:7799" privileged: true volumes: - /sbin/iptables:/worker-state/3.6.0/assets/iptables/sbin/iptables # Match the path from your logs environment: - CONCOURSE_TSA_HOST=concourse-web-1.dev - CONCOURSE_GARDEN_NETWORK=10.254.0.0/16
Note: Double-check the path /worker-state/3.6.0/assets/iptables/sbin/iptables matches what’s in your logs—if you’re using a different Concourse version, the version number in the path will change.
3. Verify Gentoo Kernel Configuration
Ensure your kernel has Conntrack support enabled. Check your current kernel config:
zcat /proc/config.gz | grep NF_CONNTRACK
You should see entries like:
CONFIG_NF_CONNTRACK=y CONFIG_NF_CONNTRACK_IPV4=y
If these are set to n or missing, you’ll need to recompile your kernel with these options enabled (follow Gentoo’s standard kernel recompilation workflow: edit /usr/src/linux/.config, run make && make modules_install && make install, then reboot).
4. Update Concourse to a Newer Version
Older versions of Concourse’s Guardian runtime have known compatibility issues with newer Linux kernels. If the above steps don’t work, try updating your base image in your Dockerfile:
FROM concourse/concourse:latest # Or a specific recent version like 7.10.0 COPY keys/tsa_host_key.pub /concourse-keys/tsa_host_key.pub COPY keys/worker_key /concourse-keys/worker_key
Final Checks
After applying these fixes, restart your worker container to test:
docker-compose down && docker-compose up -d
Monitor the logs to confirm the iptables error no longer appears.
内容的提问来源于stack exchange,提问作者smitt04

