--
You received this message because you are subscribed to the Google Groups "kubevirt-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to kubevirt-dev...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/3013b36f-4b2b-4df9-971d-414d9f1c4538n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/63c6fe34-d79a-4b99-943f-922a819fbb6en%40googlegroups.com.
I can see below error in the operator logs :{"level":"error","ts":1696594240.0308707,"logger":"cdi-operator","msg":"error getting apiserver ca bundle","error":"ConfigMap \"cdi-apiserver-signer-bundle\" not found",
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/9014c132-36fa-4777-9e7d-151c0ab00145n%40googlegroups.com.
Still, It didn't help, I deleted everything related to CDI including the namespace but still, I can see a below error message in the logs in the operator logs and this is only pod I can see under cdi namespace.{"level":"error","ts":"2023-10-06T15:34:29Z","logger":"cdi-operator","msg":"error getting apiserver ca bundle","error":"ConfigMap \"cdi-apiserver-signer-bundle\" not found",
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/c026f01a-88a7-4ab7-96b2-14172c6c537dn%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/3f028234-1a3b-4a00-b3fe-a387141ed0acn%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/6231b9d7-4dab-4e95-8baf-a4210a813751n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/CAF0u-nh%2BdRT0Hvzpn-y91j3shW5j%2BvvEO%2Bhhrb5GKv3%2B_51tGg%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/54a595c3-4042-4a71-b024-1c4fd2e3f046n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/kubevirt-dev/CAO_S94if9899LPSPdpqP2Hjo4D9v1TrAWS%2BVa3OcqMb%2BcX-8dg%40mail.gmail.com.
I appreciate the assistance, Alexander and Zang.
This feature request would be valuable if you're utilizing storage that lacks support for fsGroups.
For the time being, I have used CDI version v1.49.0 and it unblocked me to upload the data in PVC.
But now I am facing a similar permission issue with virt-launcher-vmi-windows pod while creating a VM.
I have enabled featureGate as well still getting permission denied error for path -
/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.im
Below are the logs from virt-launcher-vmi pods:
{"component":"virt-launcher","level":"info","msg":"Successfully connected to domain notify socket at /var/run/kubevirt/domain-notify-pipe.sock","pos":"client.go:170","timestamp":"2023-10-09T11:51:03.305591Z"}
{"component":"virt-launcher","level":"info","msg":"Domain name event: kwp_vmi-windows","pos":"client.go:423","timestamp":"2023-10-09T11:51:03.308164Z"}
{"component":"virt-launcher","kind":"","level":"info","msg":"Domain defined.","name":"vmi-windows","namespace":"kwp","pos":"manager.go:1002","timestamp":"2023-10-09T11:51:03.308580Z","uid":"21fb09de-e083-4635-a76b-b542faaed437"}
{"component":"virt-launcher","level":"info","msg":"DomainLifecycle event Domain event=\"defined\" detail=\"updated\" with event id 0 reason 1 received","pos":"client.go:465","timestamp":"2023-10-09T11:51:03.308593Z"}
{"component":"virt-launcher","level":"info","msg":"Monitoring loop: rate 1s start timeout 5m57s","pos":"monitor.go:181","timestamp":"2023-10-09T11:51:03.308951Z"}
{"component":"virt-launcher","level":"info","msg":"kubevirt domain status: Shutoff(5):Unknown(0)","pos":"client.go:296","timestamp":"2023-10-09T11:51:03.309867Z"}
{"component":"virt-launcher","level":"info","msg":"Domain name event: kwp_vmi-windows","pos":"client.go:423","timestamp":"2023-10-09T11:51:03.310710Z"}
{"component":"virt-launcher-monitor","level":"info","msg":"Reaped pid 90 with status 0","pos":"virt-launcher-monitor.go:125","timestamp":"2023-10-09T11:51:03.900040Z"}
{"component":"virt-launcher","level":"error","msg":"At least one cgroup controller is required: No such device or address","pos":"virCgroupDetectControllers:451","subcomponent":"libvirt","thread":"34","timestamp":"2023-10-09T11:51:03.911000Z"}
{"component":"virt-launcher","level":"error","msg":"Unable to read from monitor: Connection reset by peer","pos":"qemuMonitorIORead:423","subcomponent":"libvirt","thread":"107","timestamp":"2023-10-09T11:51:03.926000Z"}
{"component":"virt-launcher-monitor","level":"info","msg":"Reaped pid 106 with status 256","pos":"virt-launcher-monitor.go:125","timestamp":"2023-10-09T11:51:03.926665Z"}
{"component":"virt-launcher","level":"error","msg":"internal error: qemu unexpectedly closed the monitor: 2023-10-09T11:51:03.925088Z qemu-kvm: -blockdev {\"driver\":\"file\",\"filename\":\"/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img\",\"node-name\":\"libvirt-2-storage\",\"cache\":{\"direct\":true,\"no-flush\":false},\"auto-read-only\":true,\"discard\":\"unmap\"}:
Could not open '/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img': Permission denied","pos":"qemuProcessReportLogError:1971","subcomponent":"libvirt","thread":"107","timestamp":"2023-10-09T11:51:03.926000Z"}
spec:
certificateRotateStrategy: {}
configuration:
developerConfiguration:
featureGates:
- VMExport
- ExperimentalVirtiofsSupport
- Root
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Normal SuccessfulCreate 6m10s virtualmachine-controller Created virtual machine pod virt-launcher-vmi-windows-z76z6
Warning SyncFailed 6m5s virt-handler server error. command SyncVMI failed: "LibvirtError(Code=1, Domain=10, Message='internal error: process exited while connecting to monitor: 2023-10-09T11:19:21.848810Z qemu-kvm: -blockdev {\"driver\":\"file\",\"filename\":\"/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img\",\"node-name\":\"libvirt-2-storage\",\"cache\":{\"direct\":true,\"no-flush\":false},\"auto-read-only\":true,\"discard\":\"unmap\"}: Could not open '/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img': Permission denied')"
Am I missing something here ?
Thanks,
Ranjeet.
From: Alexander Wels <aw...@redhat.com>
Sent: Monday, October 9, 2023 5:27 PM
To: Zang Li <zan...@google.com>
Cc: Ranjeet Kharade <rkha...@nvidia.com>; kubevirt-dev <kubevi...@googlegroups.com>
Subject: Re: [kubevirt-dev] Re: Virtctl image-upload throwing Permission denied error for path /data/disk.img
External email: Use caution opening links or attachments |
Any idea about this error?
Is there any additional steps which I am missing apart from enable featureGate?
I don’t see anything as a DENIED in the logs, Even I have disabled the AppArmor on my worker nodes.
I can access this mentioned path(var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img) through exec but don’t know why it is reporting an Access Denied error.
k logs -f virt-launcher-vmi-windows-mhrs5
{"component":"virt-launcher","level":"info","msg":"Collected all requested hook sidecar sockets","pos":"manager.go:76","timestamp":"2023-10-11T16:55:02.127342Z"}
{"component":"virt-launcher","level":"info","msg":"Sorted all collected sidecar sockets per hook point based on their priority and name: map[]","pos":"manager.go:79","timestamp":"2023-10-11T16:55:02.128570Z"}
{"component":"virt-launcher","level":"info","msg":"Connecting to libvirt daemon: qemu:///system","pos":"libvirt.go:496","timestamp":"2023-10-11T16:55:02.129629Z"}
{"component":"virt-launcher","level":"info","msg":"Connecting to libvirt daemon failed: virError(Code=38, Domain=7, Message='Failed to connect socket to '/var/run/libvirt/libvirt-sock': No such file or directory')","pos":"libvirt.go:504","timestamp":"2023-10-11T16:55:02.129943Z"}
{"component":"virt-launcher","level":"error","msg":"At least one cgroup controller is required: No such device or address","pos":"virCgroupDetectControllers:455","subcomponent":"libvirt","thread":"33","timestamp":"2023-10-11T16:55:04.592000Z"}
{"component":"virt-launcher","level":"info","msg":"Monitoring loop: rate 1s start timeout 4m39s","pos":"monitor.go:180","timestamp":"2023-10-11T16:55:04.594693Z"}
{"component":"virt-launcher","level":"error","msg":"Unable to read from monitor: Connection reset by peer","pos":"qemuMonitorIORead:460","subcomponent":"libvirt","thread":"101","timestamp":"2023-10-11T16:55:04.606000Z"}
{"component":"virt-launcher-monitor","level":"info","msg":"Reaped pid 100 with status 256","pos":"virt-launcher-monitor.go:125","timestamp":"2023-10-11T16:55:04.606756Z"}
{"component":"virt-launcher","level":"error","msg":"internal error: qemu unexpectedly closed the monitor: 2023-10-11T16:55:04.605379Z qemu-kvm: -blockdev {\"driver\":\"file\",\"filename\":\"/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img\",\"node-name\":\"libvirt-2-storage\",\"cache\":{\"direct\":true,\"no-flush\":false},\"auto-read-only\":true,\"discard\":\"unmap\"}: Could not open '/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img': Permission denied","pos":"qemuProcessReportLogError:2051","subcomponent":"libvirt","thread":"101","timestamp":"2023-10-11T16:55:04.606000Z"}
{"component":"virt-launcher","level":"error","msg":"internal error: process exited while connecting to monitor: 2023-10-11T16:55:04.605379Z qemu-kvm: -blockdev {\"driver\":\"file\",\"filename\":\"/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img\",\"node-name\":\"libvirt-2-storage\",\"cache\":{\"direct\":true,\"no-flush\":false},\"auto-read-only\":true,\"discard\":\"unmap\"}: Could not open '/var/run/kubevirt-private/vmi-disks/pvcdisk/disk.img': Permission denied","pos":"qemuProcessReportLogError:2051","subcomponent":"libvirt","thread":"33","timestamp":"2023-10-11T16:55:04.607000Z"}
{"component":"virt-launcher-monitor","level":"info","msg":"Reaped pid 97 with status 0","pos":"virt-launcher-monitor.go:125","timestamp":"2023-10-11T16:55:04.610567Z"}
--
You received this message because you are subscribed to a topic in the Google Groups "kubevirt-dev" group.
To unsubscribe from this topic, visit
https://groups.google.com/d/topic/kubevirt-dev/72ksU4Nqg3M/unsubscribe.
To unsubscribe from this group and all its topics, send an email to
kubevirt-dev...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/kubevirt-dev/42c2aacd-4355-4196-a978-8cb3f61be941n%40googlegroups.com.