wazuh-docker icon indicating copy to clipboard operation
wazuh-docker copied to clipboard

Error response from daemon: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error setting rlimits for ready process: error setting rlimit type 8: operation not permitted: unknown

Open sapentiae opened this issue 1 year ago • 11 comments

Error response from daemon: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error setting rlimits for ready process: error setting rlimit type 8: operation not permitted: unknown

sapentiae avatar Jul 22 '23 21:07 sapentiae

Same issue on Proxmox 7.4-15 using a stndard Ubuntu LXC (22.04)

Wazuh Manager - starts fine

Wazuh Indexer; returns the message:-

Error response from daemon: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error setting rlimits for ready process: error setting rlimit type 8: operation not permitted: unknown

m1ntyduck avatar Jul 23 '23 12:07 m1ntyduck

Same issue on Proxmox 7.4-15 using a stndard Ubuntu LXC (22.04)

Wazuh Manager - starts fine

Wazuh Indexer; returns the message:-

Error response from daemon: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error setting rlimits for ready process: error setting rlimit type 8: operation not permitted: unknown

Same for me, also in Proxmox 7.4-15 but in Debian 11 standard container.

Ben-Higham avatar Jul 24 '23 15:07 Ben-Higham

Sam issue using Docker on windows whit debian dev env

Nonesence999 avatar Jul 25 '23 09:07 Nonesence999

I found someone getting the same error with Elasticsearch in another docker compose file and their solution worked for me.

In docker-compose.yml comment out the following lines then try compose up:

   # ulimits:
   #   memlock:
   #     soft: -1
   #     hard: -1
   #   nofile:
   #     soft: 65536
   #     hard: 65536

Ben-Higham avatar Jul 27 '23 13:07 Ben-Higham

Thanks @Ben-Higham this worked for me.

m1ntyduck avatar Jul 28 '23 22:07 m1ntyduck

Hello, I know this issue is a bit old but I'm facing the same issue using docker rootless. Have anyone manage to get trough this ? Thanks

p1r4t3-s4il0r avatar Nov 07 '23 09:11 p1r4t3-s4il0r

Are there any updates? having trouble with the same error.

camorobot avatar Apr 12 '24 09:04 camorobot

I found someone getting the same error with Elasticsearch in another docker compose file and their solution worked for me.

In docker-compose.yml comment out the following lines then try compose up:

   # ulimits:
   #   memlock:
   #     soft: -1
   #     hard: -1
   #   nofile:
   #     soft: 65536
   #     hard: 65536

thanks, it worked

ozoumi avatar May 15 '24 14:05 ozoumi

I found someone getting the same error with Elasticsearch in another docker compose file and their solution worked for me.

In docker-compose.yml comment out the following lines then try compose up:

   # ulimits:
   #   memlock:
   #     soft: -1
   #     hard: -1
   #   nofile:
   #     soft: 65536
   #     hard: 65536

Worked for me on Proxmox 8.2.4 using single node

lpaxton-bigwx avatar Jul 19 '24 13:07 lpaxton-bigwx

I had the same problem with Elasticsearch running in LXC on Proxmox and I don't suggest commenting out ulimits for Elasticsearch in docker-compose

If you are encountering issues related to memory locking limits (memlock) when running Elasticsearch (or other memory-intensive applications) inside LXC containers on Proxmox, you can resolve this by setting the memlock limit to unlimited for that LXC. This ensures that your application can lock the required amount of memory and avoid performance issues related to swapping.

To fix this, edit the LXC config file by adding lxc.prlimit.memlock=-1 and reboot the container.

jov-one avatar Aug 03 '24 15:08 jov-one