Re: [lxc-users] Unprivileged container woes: unable to install packages

2016-08-24 Thread jjs - mainphrame
Greetings - I built an oracle linux version of my unprivileged mailguard container, and while the package installation problem did not occur with oracle linux, the maiad daemon (a modern fork of amavisd-new) refuses to run, just as in the unprivileged centos version of this VW. I don't have a han

Re: [lxc-users] Unprivileged container woes: unable to install packages

2016-08-22 Thread jjs - mainphrame
Thanks for the tip about Oracle Linux, that's good to know. Jake On Mon, Aug 22, 2016 at 1:00 AM, Fajar A. Nugraha wrote: > On Mon, Aug 22, 2016 at 1:47 AM, Janjaap Bos wrote: > >> If installing the package in unprivileged mode was the problem, could you >> then run the image unprivileged afte

Re: [lxc-users] Unprivileged container woes: unable to install packages

2016-08-22 Thread Fajar A. Nugraha
On Mon, Aug 22, 2016 at 1:47 AM, Janjaap Bos wrote: > If installing the package in unprivileged mode was the problem, could you > then run the image unprivileged after installing the package in privileged > mode? > > Yup, that should be one way to workaround that issue. Switching between priv <-

Re: [lxc-users] Unprivileged container woes: unable to install packages

2016-08-21 Thread Janjaap Bos
If installing the package in unprivileged mode was the problem, could you then run the image unprivileged after installing the package in privileged mode? Op 21 aug. 2016 19:11 schreef "jjs - mainphrame" : > Running postfix in and of itself did not appear to be problematic, but the > maia mailgua

Re: [lxc-users] Unprivileged container woes: unable to install packages

2016-08-21 Thread jjs - mainphrame
Running postfix in and of itself did not appear to be problematic, but the maia mailguard antispam system as a whole includes postfix, clamd, spamassassin, maiad, httpd, perl and mysql, not all of which were happy running unprivileged. The factor that pushed me to a privileged container was the ina

Re: [lxc-users] Unprivileged container woes: unable to install packages

2016-08-21 Thread Ingo Baab
What were the issues, running a Mailserver as an unpriviledged LXC? I do the same.. and it seems to work without problems.. I just made the Mailports forward to the LXC with iptables.. Just curriously, -Ingo Am 20.08.2016 um 20:52 schrieb jjs - mainphrame: Greetings, I've given up on the un

Re: [lxc-users] Unprivileged container woes: unable to install packages

2016-08-20 Thread Serge E. Hallyn
unprivileged containers can not set file capabilities (until I or someone finds time to finish support for that at the kernel level). At least in Ubuntu it's considered a packaging error for install to fail if you cannot set filecaps, as seems to be happening with the httpd rpm below. Quoting jjs

Re: [lxc-users] Unprivileged container woes: unable to install packages

2016-08-20 Thread jjs - mainphrame
Greetings, I've given up on the unprivileged container for now. I've created a new container with the same role, and the same configuration except that it is privileged. The privileged version of this container is working more or less as expected. This container isn't doing anything I'd have cons

[lxc-users] Unprivileged container woes: unable to install packages

2016-08-18 Thread jjs - mainphrame
Greetings, I had decided to build an lxd version of an lxc server which had been running reliably for some time. Unfortunately, it doesn't seem to be running quite as smoothly. is some sort of special permissions hacking required? Here is one example of a problem in the new lxd container, which w