feat: raise kernel keyring quota on new PVE nodes
Lint / Shell (shellcheck) (push) Successful in 13s

Root inside every unprivileged LXC maps to one host user (uid 100000),
so all containers on a node share one keyring quota. Docker in the Gitea
runner (CT 119) exhausted the 20 KB default, and CI failed with "unable
to create session key: disk quota exceeded". Write
/etc/sysctl.d/99-keyrings.conf (maxkeys 20000, maxbytes 2000000) on PVE
nodes. Already applied by hand to all six current nodes; this covers
new and rebuilt ones.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-06 23:38:26 -04:00
co-authored by Claude Opus 5.5
parent 729835fa99
commit a11e4daaaa
2 changed files with 25 additions and 0 deletions
+1
View File
@@ -9,6 +9,7 @@
* 📦 Installs essential system packages
* 📊 Sets up Prometheus Node Exporter (v1.8.2)
* 🔍 Configures system health monitoring daemon (hwmon)
* 🔑 Raises the kernel keyring quota on PVE nodes (`/etc/sysctl.d/99-keyrings.conf`) so Docker in unprivileged LXC, like the Gitea CI runner, can keep starting containers
* ✅ Performs initial dry-run test of monitoring systems
## 📋 Prerequisites
+24
View File
@@ -64,6 +64,30 @@ else
apt-get install -y $COMMON_PKGS nvme-cli
fi
# =============================================================================
# Kernel keyring quota (PVE only)
# =============================================================================
# Root inside every unprivileged LXC maps to one host user (uid 100000), so all
# containers on a node share a single kernel keyring quota. Docker (the Gitea
# runner, CT 119) takes an entry for every container it starts and exhausts the
# 20 KB default, which breaks CI with "unable to create session key: disk quota
# exceeded". HA can move containers to any node, so every PVE node gets this.
if [[ "$PLATFORM" == "pve" ]]; then
echo "Raising kernel keyring quota for unprivileged containers..."
cat > /etc/sysctl.d/99-keyrings.conf << 'EOF'
# LotusGuild: raise the per-user kernel keyring quota.
# Root inside every unprivileged LXC maps to one host user (uid 100000), so all
# containers on a node share one keyring quota. Docker (Gitea runner, CT 119)
# takes an entry per container it starts and exhausts the 20 KB default, which
# breaks CI with "unable to create session key: disk quota exceeded".
# Managed by LotusGuild/freshStartScript.
kernel.keys.maxkeys = 20000
kernel.keys.maxbytes = 2000000
EOF
sysctl -q --load /etc/sysctl.d/99-keyrings.conf ||
echo "WARNING: could not apply keyring limits now; they take effect at next boot"
fi
# Install Node Exporter
echo "Installing Prometheus Node Exporter..."
NODE_EXPORTER_VERSION="1.8.2"