4000-520-616
欢迎来到免疫在线!(蚂蚁淘生物旗下平台)  请登录 |  免费注册 |  询价篮
主营:原厂直采,平行进口,授权代理(蚂蚁淘为您服务)
咨询热线电话
4000-520-616
当前位置: 首页 > 新闻动态 >
新闻详情
perm denied error when using rhcos with selinux enabled-开源...
来自 : CSDN技术社区 发布时间:2021-03-25

私信 访问主页

\"weixin_39996496\" weixin_39996496 2020-11-24 20:02 首页 开源项目 perm denied error when using rhcos with selinux enabled

bootkube fails with perm denied error when reading /assets/kco-config.yaml

fixdisabled selinuxrestarted bootkube, got further.

该提问来源于开源项目 openshift/installer

点赞 写回答 收藏 复制链接分享 删除 再等等 结题 再想想 10条回答

私信 访问主页

\"weixin_39608509\" weixin_39608509 3月前

Since we can t really customize the ignition configs, one way to work around this for now is:

$ cp /path/to/rhcos{,.permissive}.qcow2$ virt-edit -a /path/to/rhcos.permissive.qcow2 -m /dev/sda1 /grub2/grub.cfg$ # add enforcing 0 to the cmdline
点赞 评论 复制链接分享

私信 访问主页

\"weixin_39639518\" weixin_39639518 3月前

I don t know which problem alex was trying to fix in #137, but #134 is definitely right....

点赞 评论 复制链接分享

私信 访问主页

\"weixin_39559015\" weixin_39559015 3月前

It looks like #137 is related to this to, although I don t understand the situation clearly enough to know how #134 and #137 interact. Do we need both of them?

点赞 评论 复制链接分享

私信 访问主页

\"weixin_39961943\" weixin_39961943 3月前

Correct the /var/.../kco-config.yml file is mislabeled. Just needs to be loaded in with a volume mount telling the container engine to relabel the content.

点赞 评论 复制链接分享

私信 访问主页

\"weixin_39639518\" weixin_39639518 3月前

or all of the volume mounts should be with :z

点赞 评论 复制链接分享

私信 访问主页

\"weixin_39996496\" weixin_39996496 3月前

looks like this should be privilegedhttps://github.com/openshift/installer/blob/master/modules/bootkube/resources/bootkube.sh#L7

点赞 评论 复制链接分享

私信 访问主页

\"weixin_39996496\" weixin_39996496 3月前
journalctl | grep -i avcAug 15 13:56:33 test1-master-0.tt.testing ignition[687]: source : data:text/plain;charset utf-8;base64,LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcEFJQkFBS0NBUUVBbk5YSWtsM2VtRFdyeU03aFNPQlN1WVlqYkFYd1VaN0hwZE9YVEpTck8xbzQ1YURHCmN6QUF1ZFl5ZTVnem9zeWUzWDZXL3hNNGVJR3JCR3ZGTS9Ucno1TUdHd3dpUnRRdk5ydHJMKzBoTlFSRXB4T00KMXRRWW5yeFc4N3pzV2w5bmFBWEY5cG45RFBYU0dmOCs2aXpab3NrYk5aWmt5aVY0SzRjM2dzYVVJR2s3bXRGbwora3JqQVFzQldvQWN0Ykt5SlJITS9wSkozTUI1K0lQQkZzK0Q4OXlTQ3ZjcGVyWUZZcXRPYlF3NGpWUnI0bmhEClZpR3VrbVFYdDBDOUhETDIwWm9GT1lKbjQ0YWJKemM2TEZuaDZXYjlaa1pSNFQyalF1bThOSTdPOUlDemhCOFYKclFOdm1rRnZkQzd0K1FpQVc2L0Z3c2NUVVdYa2lNamdoUTJDK1FJREFRQUJBb0lCQUFqMlNuVGF1bHFXVG8rMgpDcmVnWWZuS0NZSWx3THJaU08xWDd3Qm9TblNrempXSS8yNGJveDc3ZDMwS2tJRFFFby96cU90QWpPeU45RmpYClU3aUpXV1JPTVg0Z0xtRS94TWJxNU5BalM4OTh3L09NTVhNaFFacm9oa3Q5VTBCQ3pXVHJWNG1rK1FuaGpqVUEKR2ZkRnd0WURpZk9BK1pkM2xxdGVHYlQyWmdhSUJmNXVMNDBMSEZqdlA3TlhlQ3dTbkFQZFBwZ1FSSENDOVEyMgprT242cFhDazM0bVVzZVI4UlVpUWhYTFpTSWFrcUxVWE1ndndHL0pGNDNQZDZFQVdiYXkveTlraWtYZDRyUk1vCkRManB2YkhyeWpyVDM0d0N0UXpCNXJZRUd1MytEVGpvNGRKQ1pHeVg2QWw0T1ZFdFMxRUxTajdmT1FBelhMYysKTEZ5SVpKRUNnWUVBd1IyNlVpU21pWlhwdGdEL1YvMUF2cVNHdEJ2clhROEliOTF3OTNCc0haNlZLNXA2WEkwUQpyOEQwUTJjczB6ckJ3cXhKVThwU0FNYituVHY1dnFjaTdyK24wV2RmbGpwOE8rYVl3V1dXYldnMFNTZVNVUCtZClBsVzdmR3NtUi9KZUxNSmxKWlRFYjBNOGVHcFlTZUZUcWhmSVUzQzVoNVFvcjY2SXVnbFhyalVDZ1lFQXorZWwKMGxNSWlQNE8vOWVjamhESFFYZE1HN3crazV5Y1ltRFRDUXg1LzEzTlhucVdyUDR0WWVFSEZ0TFQ0dFVmcU1BUgpVOUZqaTNQbzRZTjBwaU9yb1ZEd2x1QkI4dkttOFVheHdjajgxWWNMTHRZdFVCMjNHRVAvbU56Vm9WSEY0d3JjCnJwa25nZ1FDcW9VMDJrWGYzbUJ2cWZQa1p6VUxweHIrTmt0QzZqVUNnWUVBZ09ZMjExMWZTN2FrcUxkQnVKbHgKL2M0VG0yU0hWVFlUaTVkakw4WDZaRXJWaHFVMXgxRGhNbTY0bThUaVJwdVJlVDlHTW9kNDlNdmVaMVVBL2lEUgpVRXJjMlFrRzVGOWxUUlkrSDlpTzc3ZitMbFliYzdVbkNYUndFRHYwOFZEMVN5cjJHSCtVSGkvaXpQMHVzU0dWCmxwTUpRNmlhTGNUVzQyeThGbkRsOVlFQ2dZQXJNcFY0c3ZuMkJOdTIrdVN6ZS9iNnVqL2REMnJ0SHNBN2pLU3MKbjZRRmxFYmtsNUlSRmFyMlNGeEJ1TUovd2dxVzlIbGxNZjk5N1RKNUVPZyswUENMVHhiK01sQmhtMXRtakdySQp1ZXNXcnIxN0dOTkhielVvM0pBU0FlaDlZVkU5a0hjejYreVNqaVREcTNQRTJubmVhYWtwNWR3U09hcFhLVHVpCnFsYVg5UUtCZ1FDV3J5dWUxYk9pdmE2TzdHb01FQzFtOGlhd3NkLzFzZ2VTZnBJZnRWUGh6bnM2RU1PMVVHa2UKaUVhOUFaMmdCY1RXd3Y2MWpzaFgwWXhmaC9Lc1ZOVkk1cUhBbG9VOGdDUmlCblkxL2xRQy9SRGJMNzJWcjd0Ngp3cjk2bzd0WFN3dzlaY0ZKc3c1TG85K3AwYkxWUWFNMUFpYVlBUk44Zm54V3FRaVcyQ3hDTFE9PQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo ,Aug 15 13:56:34 test1-master-0.tt.testing ignition[687]: source : data:text/plain;charset utf-8;base64,LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcFFJQkFBS0NBUUVBd2MrWHdWZEFxa0hlSERuQjcwMkxOcXJaYXJ0b1ZRSTM5L2dkN2h3WnpqdnVCU1hvCmprTjFpK004dTRNRi9IWUIzdzdBZHd1N1dOeXIwN2tSazNBemZpTitBNDd4cjE1ajZ0djEraklIVDlrRDdveSsKUzBlRC8wQUM4bmFYeHdlNFdJUGV2TGU1Qm1LOTMvTkR6cjRBdXR2ZTVsUDliQnFQK25INElMck82WlF0Sm1BNgpFTmhsOHBnRGxZVFZDanBYbUxhZFBBbHEwSm1TZytSVSt5NEpyTkpybGk4NWFWRS91UW04b2gzK1BrSWhKNncyCkxaTTEva2tzNEVCQml2cUVwZUVHYXZ4TnUxUFo0YVl0S1lweVc0SHJ2R25tQ2tua3Z0VzJ1ZjFaTFgzaUl2aG4KdWdBT1AyeEFqSktxbWdSVVBYcXRIdnhaQ2RLZ3g5L0ZLaFArcFFJREFRQUJBb0lCQVFDM0VyTVV6S2ltcXdWMQp3QkV6VFJwZGoxRkVnclp3NW1HYitHRzlWQW9FUjVQMGhQU0J2Yk5CYW1zcDdRQXdrLy84aGVERUV1N3JaN2RmCmpZZk9yOFBVT1E2RnFmY2VZcGtiZHArSnNNdzdYcEZhT3RSZUk3WEozTnRyMFI1WndTOGZYYUYrdmtVbWhRczYKaW4zWXdwM0o1SHRQTXJORjlHbGdkMXVjL3hrSWhXd0Q2Q2lhQTUyRmgvUkRGYUc1bmM3cTNDNHVnNEsxeCtwUApldG5Obzd3U01aczI5bW5MS0pmR1h5NDU1RnZHQmlOQmJHLzNXL1pNT0lCKzI3aURib2l0QzIvYkZrWGJMQzJECnUrUXpOb25SNzJvZXVmTWh0aFNWUUw1WnNIU3NVRENoSkI5cEIzYWhvdlo0ZFdqWEpoYjY4bzVxdjFrQ3RuZmsKa25QUXlIeFpBb0dCQU93QUhvNm13U3QyeGVXNVh4azErWi9BR2JObXljdy9iMk9XV2dubHBWWVVYaEhGMVp2Zwpmcm1nUEZ6VWl6TGZTckVlbXNNWTV3Qk9pcTJ5cUh4TGlPMjU0MDZ3VlovTDYrLzBGTkliUE5yc1RxSDk5NDRoCnM3aGdqMmtZNklYSGdqc3ozTThkdHVmODFzYXZkc1kzZlNCMGpzYWFzS0w5citqaDROQlRpL2hiQW9HQkFOSTgKTXAxdnRyN1psamFvd1JvWG9JZm9McFJKaXZGb2lYZnptUWExZ1lQOWYyK1dpQ1NGVUdQcEZjNUN3ZGJJWm94RAp5bXlTbDhwL3JBemx4U0VMK0s1ZTZTRGhJQnJERjRWS3FnYjByNXhIYkFIMFdxcE5QQjhyejJnY0l1YWR0dzFDCnZLNHZDU1VJRUJJY2d3dkdoQkV6ZjVkY21RclNJdExJSjNiV3FaVC9Bb0dCQUpIaWdRRXRrN3VLY0VyUmpEZkoKWmNXYXVraHNBZEtBWkJycmxqMEgrR3g5cXFqUjRubTVESjB5c0IyeVJWbnRMZjdQTEZ2dHlONG5yeEl3bm5ZMwpPeTI0K3dwcGRvU1JTZ2ZLbWhSSFFoY1NmSWttdFNEbk5IR0ZQeUY0aEVRdVVCTEl2SFpMcUFWQUJvUkxjdUNVCjdJUmppTjY4UVBTQVhYMVlJK0NqeEtLQkFvR0JBTFFacThhaFlDMUkyMTFCM2dNTFFKT00vUEk5dWxDcW5ERnQKTnFlL3NBOHhpQTFCS0tvWXB0Q2dhZlREemFqQkR0Q1Vkb0hpWnpTcmdPbWZvT3Q1aFBWa0MxVUdadWxtUGUwTApGSE5YQkdYZDdaSVRFZVNZdTZ0OGJYYWp1K1pTTC9HbFBWditvVmZlKzExNG5XN21CbGR5QlpqV1U2a29jWHFlCnl1Z01aMFJqQW9HQVQ5WnY5Uk44cVBwMGRHaml1TmxGYWs3ZC9DRXBiMDI2bEovSmtkN0Z6bXVGekNrL0ZHc1QKL0w4U0x1dXZHY3dLSnFUNWZLdm9TT0FwUmdBUlhYMHpwdVZ3cGhJNWlQby9EM2VwaXJJMVlkdVZPM016WUQrWApiU3V1SFNpZU1aT0Z0aWx3NlJCQjNubnJUV0ErWHRWSCtpQVFlbUJEUnJCSnlSNWlNVjJROEFFPQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo ,Aug 15 13:57:07 test1-master-0 kernel: type 1400 audit(1534341427.214:4): avc: denied { read } for pid 1475 comm renderer name kco-config.yaml dev dm-0 ino 5728740 scontext system_u:system_r:container_t:s0:c115,c381 tcontext system_u:object_r:var_t:s0 tclass file
点赞 评论 复制链接分享

私信 访问主页

\"weixin_39996496\" weixin_39996496 3月前

tried with new image, still have issues with bootkube output:

[core-master-0 ~]$ journalctl --no-pager -u bootkube-- Logs begin at Wed 2018-08-15 13:56:27 UTC, end at Wed 2018-08-15 14:00:01 UTC. --Aug 15 13:56:48 test1-master-0 systemd[1]: Starting Bootstrap a Kubernetes cluster...Aug 15 13:56:48 test1-master-0 bash[1404]: Rendering Kubernetes core manifests...Aug 15 13:56:48 test1-master-0 bash[1404]: Unable to find image quay.io/coreos/kube-core-renderer-dev:df42b97af403702013f4739fc82cd005cfd0c766 locallyAug 15 13:56:48 test1-master-0 bash[1404]: Trying to pull repository quay.io/coreos/kube-core-renderer-dev ...Aug 15 13:56:49 test1-master-0 bash[1404]: df42b97af403702013f4739fc82cd005cfd0c766: Pulling from quay.io/coreos/kube-core-renderer-devAug 15 13:56:49 test1-master-0 bash[1404]: 4d472840d001: Pulling fs layerAug 15 13:56:49 test1-master-0 bash[1404]: dd5cfda89e72: Pulling fs layerAug 15 13:56:50 test1-master-0 bash[1404]: 4d472840d001: Verifying ChecksumAug 15 13:56:50 test1-master-0 bash[1404]: 4d472840d001: Download completeAug 15 13:56:50 test1-master-0 bash[1404]: dd5cfda89e72: Verifying ChecksumAug 15 13:56:50 test1-master-0 bash[1404]: dd5cfda89e72: Download completeAug 15 13:57:03 test1-master-0 bash[1404]: 4d472840d001: Pull completeAug 15 13:57:05 test1-master-0 bash[1404]: dd5cfda89e72: Pull completeAug 15 13:57:05 test1-master-0 bash[1404]: Digest: sha256:b7441413d170e803ca71a020863ac66f435d9b713664ba8074e994288268e712Aug 15 13:57:05 test1-master-0 bash[1404]: Status: Downloaded newer image for quay.io/coreos/kube-core-renderer-dev:df42b97af403702013f4739fc82cd005cfd0c766Aug 15 13:57:07 test1-master-0 bash[1404]: F0815 13:57:07.218416 1 main.go:24] Failure reading config from /assets/kco-config.yaml : read config from /assets/kco-config.yaml : open /assets/kco-config.yaml: permission deniedAug 15 13:57:07 test1-master-0 systemd[1]: bootkube.service: main process exited, code exited, status 255/n/aAug 15 13:57:07 test1-master-0 systemd[1]: Failed to start Bootstrap a Kubernetes cluster.Aug 15 13:57:07 test1-master-0 systemd[1]: Unit bootkube.service entered failed state.Aug 15 13:57:07 test1-master-0 systemd[1]: bootkube.service failed.

the perm denied still appears related to selinux.

点赞 评论 复制链接分享

私信 访问主页

\"weixin_39996496\" weixin_39996496 3月前

I see this will be fixed tomorrow

点赞 评论 复制链接分享

私信 访问主页

\"weixin_39996496\" weixin_39996496 3月前

this was using libvirt with rhcos qcow

点赞 评论 复制链接分享 提交 再想想 采纳 为你推荐 各位大佬,新手学C语言,写了一个函数,报这样的错误。该怎办: c语言 2个回答golang将os.ModePerm转换为字符串 string 2个回答我应该为ioutil.WriteFile的`perm`参数传递什么? file-io 2个回答启动容器进程导致“ exec:\\” / app \\“:权限被拒绝”:未知 docker 3个回答Go中Linux上的八进制文件烫发位 it技术互联网问答IT行业问题计算机技术编程语言问答 1个回答使用加密/兰特生成带有rand.Perm的排列 random 1个回答实施Heap的置换算法时Golang范围内的通道具有奇怪的行为 permutationslicerangechannels 2个回答为什么在调用OpenFile时需要设置权限? it技术互联网问答IT行业问题计算机技术编程语言问答 1个回答Golang-将uint转换为os.FileMode castingtype-conversion 1个回答为什么存储在MySQL中的日期都错了? mysqlformsphpdatabasehtmlhttp-post 3个回答notification无法显示 android-studioandroidjava 1个回答Neteller API错误:invalid_scope php 1个回答如何在Heroku上为Yii应用程序组合和缩小JS和CSS? herokuyiiyii2php 1个回答Foreach PHP错误 foreachphp 4个回答feign 通过服务名调用报错404 javajava-eeintellij-idea 3个回答npm run build 时出错 node.js 2个回答定时任务执行一段时间JVM会自动退出问题,急求大神帮忙。 jvm 0个回答java.lang.ClassFormatError 问题 it技术互联网问答IT行业问题计算机技术编程语言问答 0个回答公司的系統點擊一個功能的時候報java.lang.OutOfMemoryError: PermGen space it技术互联网问答IT行业问题计算机技术编程语言问答 0个回答 PermGen space异常 问题解决了吗?如何解决呢? 企业应用 0个回答 点击登录 提问题 欢迎建议意见 . 如何写高质量提问和回答? 采纳榜7天 被采纳次数 ProfSnail 25 幻灰龙 19 qq_34124780 154 coagenth 115 规则边缘 116 GoCityPass新加坡曼谷通票 117 cpp_learner 98 Jack_Yang(数据分析及可视化) 99 我不喜欢这个世界 810 天际的海浪 6 加急问题 500 500 基于tensorflow的模型做预测时,cpu占用率过高,如何降低程序的cpu占用率? 100 unity 设置Animation的culling type 导致游戏崩溃 100 java实现下面两个算法 100 ECDSA加密算法中,签名和验证都是需要时间的,那其时间复杂度怎么用椭圆曲线参数如阶或模p来表示呢? 75 数据库只有myd文件没有frm,myi文件,怎么打开呢 51 利用Adams联合matlab仿真求运动学反解问题 50 labview使用datasocket与c/c#程序的通信 50 python引用xlwings出问题,这个报错什么意思 ,怎么解决,谢谢大佬 50 如何用C语言实现凯撒密码对文本文件(.txt)的读取穷举暴力破解? 50 已知地图GPS坐标点A和坐标点B,获取A点往B点直线走一定距离的坐标点经纬度?

本文链接: http://permcos.immuno-online.com/view-749933.html

发布于 : 2021-03-25 阅读(0)