feat: raise kernel keyring quota on new PVE nodes
Lint / Shell (shellcheck) (push) Successful in 13s
Lint / Shell (shellcheck) (push) Successful in 13s
Root inside every unprivileged LXC maps to one host user (uid 100000), so all containers on a node share one keyring quota. Docker in the Gitea runner (CT 119) exhausted the 20 KB default, and CI failed with "unable to create session key: disk quota exceeded". Write /etc/sysctl.d/99-keyrings.conf (maxkeys 20000, maxbytes 2000000) on PVE nodes. Already applied by hand to all six current nodes; this covers new and rebuilt ones. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -9,6 +9,7 @@
|
|||||||
* 📦 Installs essential system packages
|
* 📦 Installs essential system packages
|
||||||
* 📊 Sets up Prometheus Node Exporter (v1.8.2)
|
* 📊 Sets up Prometheus Node Exporter (v1.8.2)
|
||||||
* 🔍 Configures system health monitoring daemon (hwmon)
|
* 🔍 Configures system health monitoring daemon (hwmon)
|
||||||
|
* 🔑 Raises the kernel keyring quota on PVE nodes (`/etc/sysctl.d/99-keyrings.conf`) so Docker in unprivileged LXC, like the Gitea CI runner, can keep starting containers
|
||||||
* ✅ Performs initial dry-run test of monitoring systems
|
* ✅ Performs initial dry-run test of monitoring systems
|
||||||
|
|
||||||
## 📋 Prerequisites
|
## 📋 Prerequisites
|
||||||
|
|||||||
@@ -64,6 +64,30 @@ else
|
|||||||
apt-get install -y $COMMON_PKGS nvme-cli
|
apt-get install -y $COMMON_PKGS nvme-cli
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# =============================================================================
|
||||||
|
# Kernel keyring quota (PVE only)
|
||||||
|
# =============================================================================
|
||||||
|
# Root inside every unprivileged LXC maps to one host user (uid 100000), so all
|
||||||
|
# containers on a node share a single kernel keyring quota. Docker (the Gitea
|
||||||
|
# runner, CT 119) takes an entry for every container it starts and exhausts the
|
||||||
|
# 20 KB default, which breaks CI with "unable to create session key: disk quota
|
||||||
|
# exceeded". HA can move containers to any node, so every PVE node gets this.
|
||||||
|
if [[ "$PLATFORM" == "pve" ]]; then
|
||||||
|
echo "Raising kernel keyring quota for unprivileged containers..."
|
||||||
|
cat > /etc/sysctl.d/99-keyrings.conf << 'EOF'
|
||||||
|
# LotusGuild: raise the per-user kernel keyring quota.
|
||||||
|
# Root inside every unprivileged LXC maps to one host user (uid 100000), so all
|
||||||
|
# containers on a node share one keyring quota. Docker (Gitea runner, CT 119)
|
||||||
|
# takes an entry per container it starts and exhausts the 20 KB default, which
|
||||||
|
# breaks CI with "unable to create session key: disk quota exceeded".
|
||||||
|
# Managed by LotusGuild/freshStartScript.
|
||||||
|
kernel.keys.maxkeys = 20000
|
||||||
|
kernel.keys.maxbytes = 2000000
|
||||||
|
EOF
|
||||||
|
sysctl -q --load /etc/sysctl.d/99-keyrings.conf ||
|
||||||
|
echo "WARNING: could not apply keyring limits now; they take effect at next boot"
|
||||||
|
fi
|
||||||
|
|
||||||
# Install Node Exporter
|
# Install Node Exporter
|
||||||
echo "Installing Prometheus Node Exporter..."
|
echo "Installing Prometheus Node Exporter..."
|
||||||
NODE_EXPORTER_VERSION="1.8.2"
|
NODE_EXPORTER_VERSION="1.8.2"
|
||||||
|
|||||||
Reference in New Issue
Block a user