</span></code></pre></div> <p>Or</p> <div class="language-text highlight"><pre><span></span><code><span id=__span-1-1><a id=__codelineno-1-1 name=__codelineno-1-1 href=#__codelineno-1-1></a>Failed to create CoreCLR, HRESULT: 0x80070008
</span></code></pre></div> <p>Or</p> <div class="language-text highlight"><pre><span></span><code><span id=__span-2-1><a id=__codelineno-2-1 name=__codelineno-2-1 href=#__codelineno-2-1></a>WARNING :: MAIN : : can&#39;t start new thread
</span></code></pre></div> <h3 id=resolution>Resolution<a class=headerlink href=#resolution title="Permanent link">&para;</a></h3> <h4 id=long-term-fix>Long-Term Fix<a class=headerlink href=#long-term-fix title="Permanent link">&para;</a></h4> <p>Upgrade your Docker engine to at least version <code>20.10.10</code>. <a href=>Refer to the official Docker docs for installation/update details.</a></p> <h4 id=short-term-fix>Short-Term Fix<a class=headerlink href=#short-term-fix title="Permanent link">&para;</a></h4> <p>For Docker CLI, run your container with:</p> <p><code>--security-opt seccomp=unconfined</code></p> <p>For Docker Compose, run your container with:</p> <div class="language-yaml highlight"><pre><span></span><code><span id=__span-3-1><a id=__codelineno-3-1 name=__codelineno-3-1 href=#__codelineno-3-1></a><span class=nt>security_opt</span><span class=p>:</span>
</span><span id=__span-3-2><a id=__codelineno-3-2 name=__codelineno-3-2 href=#__codelineno-3-2></a><span class=w> </span><span class="p p-Indicator">-</span><span class=w> </span><span class="l l-Scalar l-Scalar-Plain">seccomp=unconfined</span>
</span></code></pre></div> <h2 id=rdesktop>My host is incompatible with images based on rdesktop<a class=headerlink href=#rdesktop title="Permanent link">&para;</a></h2> <p>Some x86_64 hosts have issues running rdesktop based images even with the latest Docker version due to syscalls that are unknown to Docker.</p> <h3 id=symptoms_1>Symptoms<a class=headerlink href=#symptoms_1 title="Permanent link">&para;</a></h3> <p>If your host is affected you may see errors in your containers such as:</p> <div class="language-text highlight"><pre><span></span><code><span id=__span-4-1><a id=__codelineno-4-1 name=__codelineno-4-1 href=#__codelineno-4-1></a>Failed to close file descriptor for child process (Operation not permitted)
</span></code></pre></div> <h3 id=resolution_1>Resolution<a class=headerlink href=#resolution_1 title="Permanent link">&para;</a></h3> <p>For Docker CLI, run your container with:</p> <p><code>--security-opt seccomp=unconfined</code></p> <p>For Docker Compose, run your container with:</p> <div class="language-yaml highlight"><pre><span></span><code><span id=__span-5-1><a id=__codelineno-5-1 name=__codelineno-5-1 href=#__codelineno-5-1></a><span class=w> </span><span class=nt>security_opt</span><span class=p>:</span>
</span><span id=__span-5-2><a id=__codelineno-5-2 name=__codelineno-5-2 href=#__codelineno-5-2></a><span class=w> </span><span class="p p-Indicator">-</span><span class=w> </span><span class="l l-Scalar l-Scalar-Plain">seccomp=unconfined</span>
</span></code></pre></div> <h2 id=libseccomp>My host is incompatible with images based on Ubuntu Focal and Alpine 3.13 and later<a class=headerlink href=#libseccomp title="Permanent link">&para;</a></h2> <p>This only affects 32 bit installs of distros based on Debian Buster.</p> <p>This is due to a bug in the libseccomp2 library (dependency of Docker itself), which is fixed. However, it's not pushed to all the repositories.</p> <p><a href=>A GitHub issue tracking this</a></p> <p>You have a few options as noted below. Options 1 is short-term, while option 2 is considered the best option if you don't plan to reinstall the device (option 3).</p> <h3 id=resolution_2>Resolution<a class=headerlink href=#resolution_2 title="Permanent link">&para;</a></h3> <p>If you decide to do option 1 or 2, you should just need to restart the container after confirming you have libseccomp2.4.4 installed.</p> <p>If 1 or 2 did not work, ensure your Docker install is at least version 20.10.0, <a href= >refer to the official Docker docs for installation.</a></p> <h4 id=manual-patch>Manual patch<a class=headerlink href=#manual-patch title="Permanent link">&para;</a></h4> <p>Manually install an updated version of the library with dpkg.</p> <div class="language-shell highlight"><pre><span></span><code><span id=__span-6-1><a id=__codelineno-6-1 name=__codelineno-6-1 href=#__codelineno-6-1></a>wget<span class=w> </span>
</span><span id=__span-6-2><a id=__codelineno-6-2 name=__codelineno-6-2 href=#__codelineno-6-2></a>sudo<span class=w> </span>dpkg<span class=w> </span>-i<span class=w> </span>libseccomp2_2.4.4-1~bpo10+1_armhf.deb
</span></code></pre></div> <div class="admonition info"> <p class=admonition-title>Info</p> <p>This url may have been updated. Find the latest by browsing <a href= >here</a>.</p> </div> <h4 id=automatic-patch>Automatic Patch<a class=headerlink href=#automatic-patch title="Permanent link">&para;</a></h4> <p>Add the backports repo for DebianBuster. As seen <a href=>here</a>.</p> <div class="language-shell highlight"><pre><span></span><code><span id=__span-7-1><a id=__codelineno-7-1 name=__codelineno-7-1 href=#__codelineno-7-1></a>sudo<span class=w> </span>apt-key<span class=w> </span>adv<span class=w> </span>--keyserver<span class=w> </span><span class=w> </span>--recv-keys<span class=w> </span>04EE7237B7D453EC<span class=w> </span>648ACFD622F3D138
</span><span id=__span-7-2><a id=__codelineno-7-2 name=__codelineno-7-2 href=#__codelineno-7-2></a><span class=nb>echo</span><span class=w> </span><span class=s2>&quot;deb buster-backports main&quot;</span><span class=w> </span><span class=p>|</span><span class=w> </span>sudo<span class=w> </span>tee<span class=w> </span>-a<span class=w> </span>/etc/apt/sources.list.d/buster-backports.list
</span><span id=__span-7-3><a id=__codelineno-7-3 name=__codelineno-7-3 href=#__codelineno-7-3></a>sudo<span class=w> </span>apt<span class=w> </span>update
</span><span id=__span-7-4><a id=__codelineno-7-4 name=__codelineno-7-4 href=#__codelineno-7-4></a>sudo<span class=w> </span>apt<span class=w> </span>install<span class=w> </span>-t<span class=w> </span>buster-backports<span class=w> </span>libseccomp2
</span></code></pre></div> <h4 id=move-to-a-compatible-os>Move to a compatible OS<a class=headerlink href=#move-to-a-compatible-os title="Permanent link">&para;</a></h4> <p>Reinstall/update your OS to a version that still gets updates.</p> <ul> <li>Any distro based on DebianStretch does not seem to have this package available</li> <li>DebianBuster based distros can get the package trough backports, as outlined in point 2.</li> </ul> <div class="admonition info"> <p class=admonition-title>Info</p> <p>RaspberryPI OS (formerly Raspbian) Can be upgraded to run with a 64bit kernel</p> </div> <h3 id=symptoms_2>Symptoms<a class=headerlink href=#symptoms_2 title="Permanent link">&para;</a></h3> <ul> <li>502 errors in <strong>Jellyfin</strong> as seen in <a href=>linuxserver/docker-jellyfin#71</a></li> <li><code>Error starting framework core</code> messages in the docker log for <strong>Plex</strong>. <a href=>linuxserver/docker-plex#247</a></li> <li>No WebUI for <strong>Radarr</strong>, even though the container is running. <a href=>linuxserver/docker-radarr#118</a></li> <li>Images based on our Nginx base-image(Nextcloud, SWAG, Nginx, etc.) fails to generate a certificate, with a message similar to <code>error getting time:crypto/asn1/a_time.c:330</code></li> <li><code>docker exec &lt;container-name&gt; date</code> returns 1970</li> </ul> <h2 id=storage>My host filesystem is incompatible with my docker storage driver<a class=headerlink href=#storage title="Permanent link">&para;</a></h2> <p>Some host file systems types are not compatible with the default storage driver of docker (overlay2)</p> <h3 id=symptoms_3>Symptoms<a class=headerlink href=#symptoms_3 title="Permanent link">&para;</a></h3> <p>If your host is affected you may see errors in your containers such as:</p> <div class="language-text highlight"><pre><span></span><code><span id=__span-8-1><a id=__codelineno-8-1 name=__codelineno-8-1 href=#__codelineno-8-1></a>ERROR Found no accessible config files
</span></code></pre></div> <p>or</p> <div class="language-text highlight"><pre><span></span><code><span id=__span-9-1><a id=__codelineno-9-1 name=__codelineno-9-1 href=#__codelineno-9-1></a>Directory not empty. This directory contains an empty ignorecommands sub-directory
</span></code></pre></div> <h3 id=resolution_3>Resolution<a class=headerlink href=#resolution_3 title="Permanent link">&para;</a></h3> <p>As shown in <a href=>Docker docs</a></p> <p>A host filesystem of zfs requires a docker storage driver of zfs and a host file system of btrfs requires a docker storage driver of btrfs. Correcting this oversight will resolve the issue. This is not something that a container change will resolve.</p> <h2 id=lscr>What is<a class=headerlink href=#lscr title="Permanent link">&para;</a></h2> <p>LSCR is a vanity url for our images, this is provided to us in collaboration with <a href= ></a>. It is not a dedicated docker registry, rather a redirection service. As of writing it redirects to GitHub Container Registry (</p> <p>Aside from giving us the ability to redirect to another backend, if necessary, it also exposes telemetry about pulls, historically only available to the backend provider. We base some decisions on this data, as it gives us a somewhat realistic usage overview (relative to just looking at pulls on DockerHub).</p> <p>We have some blog posts related to how we utilize Scarf:</p> <ul> <li><a href=>End of an Arch</a></li> <li><a href=>Unravelling Some Stats</a></li> <li><a href=>Wrap Up Warm For Winter</a></li> </ul> <h3 id=lscr-no-connect>I cannot connect to<a class=headerlink href=#lscr-no-connect title="Permanent link">&para;</a></h3> <p>Due to the nature of Scarf as a Docker gateway which gathers usage metrics, some overzealous privacy-focused blocklists will include its domains.</p> <p>If you want to help us in getting a better overview of how people use our containers, you should add <code></code> to the allowlist in your blocklist solution.</p> <p>Alternatively, you can use Docker Hub or GHCR directly to pull your images, although be aware that all public registries gather user metrics, so this doesn't provide you with any real benefit in that area.</p> <p>If Scarf is on the blocklist, you will get an error message like this when trying to pull an image:</p> <div class="language-text highlight"><pre><span></span><code><span id=__span-10-1><a id=__codelineno-10-1 name=__codelineno-10-1 href=#__codelineno-10-1></a>Error response from daemon: Get &quot;;: dial tcp: lookup no such host
</span></code></pre></div> <p>This is, however, a generic message. To rule out a service-interruption, you should also see if you can resolve the backend provider.</p> <p>Using dig:</p> <div class="language-shell highlight"><pre><span></span><code><span id=__span-11-1><a id=__codelineno-11-1 name=__codelineno-11-1 href=#__codelineno-11-1></a>dig<span class=w> </span><span class=w> </span>+short
</span><span id=__span-11-2><a id=__codelineno-11-2 name=__codelineno-11-2 href=#__codelineno-11-2></a>dig<span class=w> </span><span class=w> </span>+short
</span></code></pre></div> <p>Using nslookup:</p> <div class="language-shell highlight"><pre><span></span><code><span id=__span-12-1><a id=__codelineno-12-1 name=__codelineno-12-1 href=#__codelineno-12-1></a>nslookup<span class=w> </span>
</span><span id=__span-12-2><a id=__codelineno-12-2 name=__codelineno-12-2 href=#__codelineno-12-2></a>nslookup<span class=w> </span>
</span></code></pre></div> <p>If you only got a response from ghcr, chances are that Scarf is on the blocklist.</p> <h2 id=strict-proxy>I want to reverse proxy an application which defaults to https with a self-signed certificate<a class=headerlink href=#strict-proxy title="Permanent link">&para;</a></h2> <h3 id=strict-proxy-traefik>Traefik<a class=headerlink href=#strict-proxy-traefik title="Permanent link">&para;</a></h3> <p>In this example, we will configure a serverTransport rule we can apply to a service, as well as telling Traefik to use https on the backend for the service.</p> <p>Create a <a href=>ServerTransport</a> in your dynamic Traefik configuration; we are calling ours <code>ignorecert</code>.</p> <div class="language-text highlight"><pre><span></span><code><span id=__span-13-1><a id=__codelineno-13-1 name=__codelineno-13-1 href=#__codelineno-13-1></a> http:
</span><span id=__span-13-2><a id=__codelineno-13-2 name=__codelineno-13-2 href=#__codelineno-13-2></a> serversTransports:
</span><span id=__span-13-3><a id=__codelineno-13-3 name=__codelineno-13-3 href=#__codelineno-13-3></a> ignorecert:
</span><span id=__span-13-4><a id=__codelineno-13-4 name=__codelineno-13-4 href=#__codelineno-13-4></a> insecureSkipVerify: true
</span></code></pre></div> <p>Then on our <code>foo</code> service we tell it to use this rule, as well as telling Traefik the backend is running on https.</p> <div class="language-text highlight"><pre><span></span><code><span id=__span-14-1><a id=__codelineno-14-1 name=__codelineno-14-1 href=#__codelineno-14-1></a> -
</span><span id=__span-14-2><a id=__codelineno-14-2 name=__codelineno-14-2 href=#__codelineno-14-2></a> -
October 20, 2023
November 28, 2022