How to set "cap-add=NET_ADMIN" ?

1,671 views
Skip to first unread message

Anirban D

unread,
Feb 24, 2018, 7:45:03 AM2/24/18
to Nomad
I am using Nomad v-0.6.2 and want to set the Capability NET_ADMIN via nomad job.
I get the error "Cap_add is an invalid field".
Is there a way to do so. 

I am currently adding the flag "docker.caps.whitelist = "ALL" " in Jobspec.
And adding the "cap_add" : ["NET_ADMIN"]" in Tasks section of .nomad file.

If there is any other way I can configure this, it would be helpful.

P.S. I am trying to run a Dnsmasq job, and need the "cap-add" & "net=host" flags to allow the docker container to listen to UDP port.

Filip Ochnik

unread,
Feb 25, 2018, 3:17:37 AM2/25/18
to Nomad
Hey,

As I said in the merge request, this feature will be available in v0.8.0. It's not present in v0.6.2, hence the error you get.

In case you update to v0.8.0 once it is released, you will also have to whitelist NET_ADMIN on the node that this job is supposed to run on.

yogesh kumar

unread,
Feb 26, 2018, 12:29:30 AM2/26/18
to Nomad
Hi Filip,

Thanks for providing more information.We have below queries on this:
1. Is there any workaround to pick any user-level branch for development purpose which has feature support to " whitelist NET_ADMIN on the node ".
2. Any announced date for v0.8.0 release(approx).

Best Regards,
Yogesh Kumar

Filip Ochnik

unread,
Feb 26, 2018, 3:08:30 AM2/26/18
to Nomad
Hey Yogesh,

1. None that I'm aware of, sorry.
2. I don't know, you will have to wait for an input from someone on the HashiCorp team.

Best,
Filip

yogesh kumar

unread,
Feb 26, 2018, 5:49:05 AM2/26/18
to Nomad
Thanks!  But In case you will come to know. Please drop me info in same mail chain.

Regards,
Yogesh

Shantanu Gadgil

unread,
Apr 1, 2018, 12:16:55 PM4/1/18
to Nomad
Hi folks,
0.8.0-rc1 has been announced.

me me

unread,
Apr 4, 2018, 11:34:30 AM4/4/18
to Shantanu Gadgil, Nomad
Thanks a lot for the update Shantanu !!

Regards,
Anirban Debnath

On Sun, Apr 1, 2018 at 9:46 PM, Shantanu Gadgil <shantan...@gmail.com> wrote:
Hi folks,
0.8.0-rc1 has been announced.

--
This mailing list is governed under the HashiCorp Community Guidelines - https://www.hashicorp.com/community-guidelines.html. Behavior in violation of those guidelines may result in your removal from this mailing list.

GitHub Issues: https://github.com/hashicorp/nomad/issues
IRC: #nomad-tool on Freenode
---
You received this message because you are subscribed to a topic in the Google Groups "Nomad" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/nomad-tool/_YybOP4JE-Y/unsubscribe.
To unsubscribe from this group and all its topics, send an email to nomad-tool+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/nomad-tool/caaa4315-3f4b-48a3-9138-6715b4123dce%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply all
Reply to author
Forward
0 new messages