feat: raise kernel keyring quota on new PVE nodes
Lint / Shell (shellcheck) (push) Successful in 13s
Lint / Shell (shellcheck) (push) Successful in 13s
Root inside every unprivileged LXC maps to one host user (uid 100000), so all containers on a node share one keyring quota. Docker in the Gitea runner (CT 119) exhausted the 20 KB default, and CI failed with "unable to create session key: disk quota exceeded". Write /etc/sysctl.d/99-keyrings.conf (maxkeys 20000, maxbytes 2000000) on PVE nodes. Already applied by hand to all six current nodes; this covers new and rebuilt ones. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -9,6 +9,7 @@
|
||||
* 📦 Installs essential system packages
|
||||
* 📊 Sets up Prometheus Node Exporter (v1.8.2)
|
||||
* 🔍 Configures system health monitoring daemon (hwmon)
|
||||
* 🔑 Raises the kernel keyring quota on PVE nodes (`/etc/sysctl.d/99-keyrings.conf`) so Docker in unprivileged LXC, like the Gitea CI runner, can keep starting containers
|
||||
* ✅ Performs initial dry-run test of monitoring systems
|
||||
|
||||
## 📋 Prerequisites
|
||||
|
||||
@@ -64,6 +64,30 @@ else
|
||||
apt-get install -y $COMMON_PKGS nvme-cli
|
||||
fi
|
||||
|
||||
# =============================================================================
|
||||
# Kernel keyring quota (PVE only)
|
||||
# =============================================================================
|
||||
# Root inside every unprivileged LXC maps to one host user (uid 100000), so all
|
||||
# containers on a node share a single kernel keyring quota. Docker (the Gitea
|
||||
# runner, CT 119) takes an entry for every container it starts and exhausts the
|
||||
# 20 KB default, which breaks CI with "unable to create session key: disk quota
|
||||
# exceeded". HA can move containers to any node, so every PVE node gets this.
|
||||
if [[ "$PLATFORM" == "pve" ]]; then
|
||||
echo "Raising kernel keyring quota for unprivileged containers..."
|
||||
cat > /etc/sysctl.d/99-keyrings.conf << 'EOF'
|
||||
# LotusGuild: raise the per-user kernel keyring quota.
|
||||
# Root inside every unprivileged LXC maps to one host user (uid 100000), so all
|
||||
# containers on a node share one keyring quota. Docker (Gitea runner, CT 119)
|
||||
# takes an entry per container it starts and exhausts the 20 KB default, which
|
||||
# breaks CI with "unable to create session key: disk quota exceeded".
|
||||
# Managed by LotusGuild/freshStartScript.
|
||||
kernel.keys.maxkeys = 20000
|
||||
kernel.keys.maxbytes = 2000000
|
||||
EOF
|
||||
sysctl -q --load /etc/sysctl.d/99-keyrings.conf ||
|
||||
echo "WARNING: could not apply keyring limits now; they take effect at next boot"
|
||||
fi
|
||||
|
||||
# Install Node Exporter
|
||||
echo "Installing Prometheus Node Exporter..."
|
||||
NODE_EXPORTER_VERSION="1.8.2"
|
||||
|
||||
Reference in New Issue
Block a user